Vulnerability identifier: #VU9994
Vulnerability risk: Low
CVSSv4.0: 6.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-190
Exploitation vector: Local network
Exploit availability: No
Vulnerable software:
VMware Fusion
Client/Desktop applications /
Virtualization software
VMware Workstation
Client/Desktop applications /
Virtualization software
Vendor: VMware, Inc
Description
The vulnerability allows an adjacent attacker to gain elevated privileges on the target system.
The weakness exists on the systems with IPv6 mode enabled due to integer overflow in the VMware NAT service. An adjacent attacker can trigger memory corruption and execute arbitrary code with elevated privileges.
Mitigation
The vulnerability is addressed in the following version: 8.5.10, 10.1.1, 12.5.9, 14.1.1.
Vulnerable software versions
VMware Fusion: 8.0 - 10.1.0
VMware Workstation: 12.0.0 - 14.1
External links
https://www.vmware.com/security/advisories/VMSA-2018-0005.html
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.