#VU14413 Out-of-bounds write in VMware Workstation and VMware Fusion - CVE-2018-6973

 

#VU14413 Out-of-bounds write in VMware Workstation and VMware Fusion - CVE-2018-6973

Published: August 14, 2018 / Updated: August 15, 2018


Vulnerability identifier: #VU14413
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-6973
CWE-ID: CWE-787
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
VMware Workstation
VMware Fusion
Software vendor:
VMware, Inc

Description

The vulnerability allows an adjacent attacker to execute arbitrary code on the target system.

The vulnerability exists due to out-of-bounds write in the e1000 device. An adjacent attacker can trigger memory corruption and execute arbitrary code withe elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Update Workstation to version 14.1.3.
Update Fusion to version 10.1.3.

External links