Vulnerability Name: | CVE-2018-6969 (CCN-146404) | ||||||||||||
Assigned: | 2018-07-12 | ||||||||||||
Published: | 2018-07-12 | ||||||||||||
Updated: | 2018-09-11 | ||||||||||||
Summary: | VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on the guest VMs. In order to be able to exploit this issue, file sharing must be enabled. | ||||||||||||
CVSS v3 Severity: | 7.0 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.1 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-125 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-6969 Source: BID Type: Third Party Advisory, VDB Entry 104737 Source: CCN Type: BID-104737 VMware Tools HGFS CVE-2018-6969 Local Information Disclosure Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1041291 Source: XF Type: UNKNOWN vmware-cve20186969-info-disc(146404) Source: CCN Type: VMware Security Advisory VMSA-2018-0017 VMware Tools update addresses an out-of-bounds read vulnerability Source: CONFIRM Type: Patch, Vendor Advisory https://www.vmware.com/security/advisories/VMSA-2018-0017.html | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |