VMware Security Advisories NOV 2018

VMware announced on last Friday that they found a vulnerability which affect hosts contain VMs running with VMXNET3 due to several reasons, and this vulnarability affected VMware ESXi, Workstation, and Fusion updates address uninitialized stack memory usage.

Problem Description

VMware ESXi, Fusion and Workstation contain uninitialized stack memory usage in the vmxnet3 virtual network adapter. This issue may allow a guest to execute code on the host. The issue is present if vmxnet3 is enabled. Non-vmxnet3 virtual adapters are not affected by this issue.

VMware would like to thank the organizers of GeekPwn2018 and security researcher Zhangyanyu of Chaitin Tech for reporting this issue to us.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2018-6981 to this issue.

Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available.

To check all details and update links for each version of ESXi, Workstation, and Fusion please check below VMware official link.


Leave a Reply

Your email address will not be published. Required fields are marked *