Vulnerability Name:

CVE-2018-6972 (CCN-147146)

Assigned:2018-07-19
Published:2018-07-19
Updated:2022-06-02
Summary:VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi550-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain a denial-of-service vulnerability due to NULL pointer dereference issue in RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
5.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-476
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2018-6972

Source: CCN
Type: SECTRACK ID: 1041356
VMware Workstation/Fusion Null Pointer Dereference in RPC Handler Lets Local Users on a Guest System Cause Denial of Service Conditions on Their Guest System

Source: CCN
Type: SECTRACK ID: 1041357
VMware ESXi Null Pointer Dereference in RPC Handler Lets Local Users on a Guest System Cause Denial of Service Conditions on Their Guest System

Source: BID
Type: Third Party Advisory, VDB Entry
104884

Source: CCN
Type: BID-104884
Multiple VMware Products CVE-2018-6972 Denial of Service Vulnerability

Source: SECTRACK
Type: Broken Link, Third Party Advisory, VDB Entry
1041356

Source: SECTRACK
Type: Broken Link, Third Party Advisory, VDB Entry
1041357

Source: XF
Type: UNKNOWN
vmware-cve20186972-dos(147146)

Source: CCN
Type: IBM Security Bulletin 728587 (PureApplication System)
IBM PureApplication System is affected by a vulnerability in VMWare component (CVE-2018-6972)

Source: CCN
Type: VMware Security Advisory VMSA-2018-0018
VMware Horizon View Agent, VMware ESXi, Workstation, and Fusion updates resolve multiple security issues

Source: CONFIRM
Type: Patch, Vendor Advisory
https://www.vmware.com/security/advisories/VMSA-2018-0018.html

Source: CCN
Type: ZDI-18-779
VMware Workstation SetGuestInfo Null Pointer Dereference Denial of Service Vulnerability

Vulnerable Configuration:Configuration 1:
  • cpe:/a:vmware:workstation:*:*:*:*:*:*:*:* (Version >= 14.0 and < 14.1.2)

  • Configuration 2:
  • cpe:/a:vmware:fusion:*:*:*:*:*:*:*:* (Version >= 10.0 and < 10.1.2)
  • AND
  • cpe:/o:apple:mac_os_x:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:vmware:esxi:6.0:-:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:-:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707201:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707202:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707203:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707204:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707205:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707206:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707207:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707208:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.7:-:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.7:670-201806001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201701001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201703001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707103:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707209:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707210:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707211:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707212:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707213:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707214:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707215:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707216:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707217:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707218:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707219:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707220:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707221:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:2:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201703002:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201704001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201710001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201712001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201803001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201806001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201504401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201505401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507402:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507403:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507404:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507405:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507406:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507407:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509201:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509202:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509203:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509204:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509205:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509206:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509207:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509208:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509209:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509210:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201510401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201511401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601402:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601403:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601404:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601405:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201602401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:5.5:-:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:5.5:1:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:5.5:2:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:5.5:3a:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:5.5:3b:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:5.5:550-20170901001s:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:1:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:1a:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:1b:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:2:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:3:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:3a:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603201:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603202:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603203:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603204:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603205:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603206:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603207:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603208:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201605401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201608101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201608401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201608402:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201608403:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201608404:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201608405:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201610410:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201611401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201611402:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201611403:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702201:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702202:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702203:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702204:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702205:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702206:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702207:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702208:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702209:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702210:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702211:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702212:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201703401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201706101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201706102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201706103:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:5.5:550-20170904001:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:vmware:esxi:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:workstation:14.0:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:10.0:*:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.7:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:pureapplication_system:2.2.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.5.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    vmware workstation *
    vmware fusion *
    apple mac os x -
    vmware esxi 6.0 -
    vmware esxi 6.5 -
    vmware esxi 6.5 650-201707201
    vmware esxi 6.5 650-201707202
    vmware esxi 6.5 650-201707203
    vmware esxi 6.5 650-201707204
    vmware esxi 6.5 650-201707205
    vmware esxi 6.5 650-201707206
    vmware esxi 6.5 650-201707207
    vmware esxi 6.5 650-201707208
    vmware esxi 6.7 -
    vmware esxi 6.7 670-201806001
    vmware esxi 6.5 650-201701001
    vmware esxi 6.5 650-201703001
    vmware esxi 6.5 650-201707101
    vmware esxi 6.5 650-201707102
    vmware esxi 6.5 650-201707103
    vmware esxi 6.5 650-201707209
    vmware esxi 6.5 650-201707210
    vmware esxi 6.5 650-201707211
    vmware esxi 6.5 650-201707212
    vmware esxi 6.5 650-201707213
    vmware esxi 6.5 650-201707214
    vmware esxi 6.5 650-201707215
    vmware esxi 6.5 650-201707216
    vmware esxi 6.5 650-201707217
    vmware esxi 6.5 650-201707218
    vmware esxi 6.5 650-201707219
    vmware esxi 6.5 650-201707220
    vmware esxi 6.5 650-201707221
    vmware esxi 6.5 2
    vmware esxi 6.5 650-201703002
    vmware esxi 6.5 650-201704001
    vmware esxi 6.5 650-201710001
    vmware esxi 6.5 650-201712001
    vmware esxi 6.5 650-201803001
    vmware esxi 6.5 650-201806001
    vmware esxi 6.0 600-201504401
    vmware esxi 6.0 600-201505401
    vmware esxi 6.0 600-201507101
    vmware esxi 6.0 600-201507102
    vmware esxi 6.0 600-201507401
    vmware esxi 6.0 600-201507402
    vmware esxi 6.0 600-201507403
    vmware esxi 6.0 600-201507404
    vmware esxi 6.0 600-201507405
    vmware esxi 6.0 600-201507406
    vmware esxi 6.0 600-201507407
    vmware esxi 6.0 600-201509101
    vmware esxi 6.0 600-201509102
    vmware esxi 6.0 600-201509201
    vmware esxi 6.0 600-201509202
    vmware esxi 6.0 600-201509203
    vmware esxi 6.0 600-201509204
    vmware esxi 6.0 600-201509205
    vmware esxi 6.0 600-201509206
    vmware esxi 6.0 600-201509207
    vmware esxi 6.0 600-201509208
    vmware esxi 6.0 600-201509209
    vmware esxi 6.0 600-201509210
    vmware esxi 6.0 600-201510401
    vmware esxi 6.0 600-201511401
    vmware esxi 6.0 600-201601101
    vmware esxi 6.0 600-201601102
    vmware esxi 6.0 600-201601401
    vmware esxi 6.0 600-201601402
    vmware esxi 6.0 600-201601403
    vmware esxi 6.0 600-201601404
    vmware esxi 6.0 600-201601405
    vmware esxi 6.0 600-201602401
    vmware esxi 5.5 -
    vmware esxi 5.5 1
    vmware esxi 5.5 2
    vmware esxi 5.5 3a
    vmware esxi 5.5 3b
    vmware esxi 5.5 550-20170901001s
    vmware esxi 6.0 1
    vmware esxi 6.0 1a
    vmware esxi 6.0 1b
    vmware esxi 6.0 2
    vmware esxi 6.0 3
    vmware esxi 6.0 3a
    vmware esxi 6.0 600-201603101
    vmware esxi 6.0 600-201603102
    vmware esxi 6.0 600-201603201
    vmware esxi 6.0 600-201603202
    vmware esxi 6.0 600-201603203
    vmware esxi 6.0 600-201603204
    vmware esxi 6.0 600-201603205
    vmware esxi 6.0 600-201603206
    vmware esxi 6.0 600-201603207
    vmware esxi 6.0 600-201603208
    vmware esxi 6.0 600-201605401
    vmware esxi 6.0 600-201608101
    vmware esxi 6.0 600-201608401
    vmware esxi 6.0 600-201608402
    vmware esxi 6.0 600-201608403
    vmware esxi 6.0 600-201608404
    vmware esxi 6.0 600-201608405
    vmware esxi 6.0 600-201610410
    vmware esxi 6.0 600-201611401
    vmware esxi 6.0 600-201611402
    vmware esxi 6.0 600-201611403
    vmware esxi 6.0 600-201702101
    vmware esxi 6.0 600-201702102
    vmware esxi 6.0 600-201702201
    vmware esxi 6.0 600-201702202
    vmware esxi 6.0 600-201702203
    vmware esxi 6.0 600-201702204
    vmware esxi 6.0 600-201702205
    vmware esxi 6.0 600-201702206
    vmware esxi 6.0 600-201702207
    vmware esxi 6.0 600-201702208
    vmware esxi 6.0 600-201702209
    vmware esxi 6.0 600-201702210
    vmware esxi 6.0 600-201702211
    vmware esxi 6.0 600-201702212
    vmware esxi 6.0 600-201703401
    vmware esxi 6.0 600-201706101
    vmware esxi 6.0 600-201706102
    vmware esxi 6.0 600-201706103
    vmware esxi 5.5 550-20170904001
    vmware esxi 6.0
    vmware esxi 6.5
    vmware workstation 14.0
    vmware fusion 10.0
    vmware esxi 6.7
    ibm pureapplication system 2.2.3.0
    ibm pureapplication system 2.2.3.1
    ibm pureapplication system 2.2.3.2
    ibm pureapplication system 2.2.4.0
    ibm pureapplication system 2.2.5.0
    ibm pureapplication system 2.2.5.1
    ibm pureapplication system 2.2.5.2
    ibm pureapplication system 2.2.5.3