#VU15377 Out-of-bounds read in VMware ESXi - CVE-2018-6974
Published: October 16, 2018 / Updated: October 17, 2018
VMware ESXi
VMware, Inc
Description
The vulnerability allows an adjacent attacker to gain elevated privileges on the target system.
The vulnerability exists due to out-of-bounds read condition in the SVGA device. An adjacent attacker can send a specially crafted request that submits malicious input to the targeted host system. A successful exploit could trigger an out-of-bounds read condition and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.