#VU15787 Stack-based buffer overflow in VMware ESXi - CVE-2018-6982
Published: November 9, 2018
Vulnerability identifier: #VU15787
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-6982
CWE-ID: CWE-121
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
VMware ESXi
VMware ESXi
Software vendor:
VMware, Inc
VMware, Inc
Description
The vulnerability allows an adjacent attacker to obtain potentially sensitive information on the target system.
The weakness exists due to uninitialized stack memory usage in the vmxnet3 virtual network adapter. A remote attacker can trigger memory corruption if vmxnet3 is enabled and access arbitrary data.
Remediation
Install update from vendor's website.