Vulnerability Name:

CVE-2018-6974 (CCN-151361)

Assigned:2018-10-16
Published:2018-10-16
Updated:2022-06-02
Summary:VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds read vulnerability in SVGA device. This issue may allow a guest to execute code on the host.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-125
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2018-6974

Source: CCN
Type: IBM Security Bulletin 795276 (PureApplication System)
IBM PureApplication System is affected by a vulnerability in VMWare component (CVE-2018-6974)

Source: BID
Type: Third Party Advisory, VDB Entry
105660

Source: CCN
Type: BID-105660
Multiple VMware Products CVE-2018-6974 Local Heap-Based Buffer Overflow Vulnerability

Source: SECTRACK
Type: Broken Link, Third Party Advisory, VDB Entry
1041875

Source: SECTRACK
Type: Broken Link, Third Party Advisory, VDB Entry
1041876

Source: XF
Type: UNKNOWN
vmware-cve20186974-code-exec(151361)

Source: CCN
Type: VMSA-2018-0026
VMware ESXi, Workstation, and Fusion updates address an out-of-bounds read vulnerability

Source: CONFIRM
Type: Patch, Vendor Advisory
https://www.vmware.com/security/advisories/VMSA-2018-0026.html

Source: CCN
Type: ZDI-18-1242
VMware Workstation SVGA Heap-based Buffer Overflow Privilege Escalation Vulnerability

Vulnerable Configuration:Configuration 1:
  • cpe:/a:vmware:workstation:*:*:*:*:*:*:*:* (Version >= 14.0 and < 14.1.3)

  • Configuration 2:
  • cpe:/a:vmware:fusion:*:*:*:*:*:*:*:* (Version >= 10.0 and < 10.1.3)
  • AND
  • cpe:/o:apple:mac_os_x:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:vmware:esxi:6.0:-:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:-:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707201:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707202:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707203:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707204:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707205:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707206:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707207:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707208:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.7:-:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.7:670-201806001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.7:670-201807001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.7:670-201808001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707103:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707209:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707210:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707211:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707212:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707213:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707214:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707215:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707216:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707217:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707218:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707219:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707220:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201707221:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.7:670-201810001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:2:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201701001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201703001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201703002:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201704001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201710001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201712001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201803001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201806001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:650-201808001:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201504401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201505401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507402:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507403:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507404:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507405:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507406:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201507407:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509201:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509202:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509203:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509204:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509205:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509206:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509207:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509208:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509209:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201509210:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201510401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201511401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601402:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601403:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:1:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:1a:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:1b:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:2:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:3:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:3a:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601404:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201601405:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201602401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603201:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603202:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603203:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603204:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603205:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603206:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603207:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201603208:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201605401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201608101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201608401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201608402:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201608403:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201608404:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201608405:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201610410:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201611401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201611402:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201611403:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702201:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702202:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702203:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702204:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702205:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702206:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702207:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702208:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702209:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702210:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702211:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201702212:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201703401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201706101:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201706102:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201706103:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201706401:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201706402:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201706403:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.0:600-201710301:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:vmware:esxi:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.5:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:workstation:14.0:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:10.0:*:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.7:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:pureapplication_system:2.2.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:pureapplication_system:2.2.5.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    vmware workstation *
    vmware fusion *
    apple mac os x -
    vmware esxi 6.0 -
    vmware esxi 6.5 -
    vmware esxi 6.5 650-201707201
    vmware esxi 6.5 650-201707202
    vmware esxi 6.5 650-201707203
    vmware esxi 6.5 650-201707204
    vmware esxi 6.5 650-201707205
    vmware esxi 6.5 650-201707206
    vmware esxi 6.5 650-201707207
    vmware esxi 6.5 650-201707208
    vmware esxi 6.7 -
    vmware esxi 6.7 670-201806001
    vmware esxi 6.7 670-201807001
    vmware esxi 6.7 670-201808001
    vmware esxi 6.5 650-201707101
    vmware esxi 6.5 650-201707102
    vmware esxi 6.5 650-201707103
    vmware esxi 6.5 650-201707209
    vmware esxi 6.5 650-201707210
    vmware esxi 6.5 650-201707211
    vmware esxi 6.5 650-201707212
    vmware esxi 6.5 650-201707213
    vmware esxi 6.5 650-201707214
    vmware esxi 6.5 650-201707215
    vmware esxi 6.5 650-201707216
    vmware esxi 6.5 650-201707217
    vmware esxi 6.5 650-201707218
    vmware esxi 6.5 650-201707219
    vmware esxi 6.5 650-201707220
    vmware esxi 6.5 650-201707221
    vmware esxi 6.7 670-201810001
    vmware esxi 6.5 2
    vmware esxi 6.5 650-201701001
    vmware esxi 6.5 650-201703001
    vmware esxi 6.5 650-201703002
    vmware esxi 6.5 650-201704001
    vmware esxi 6.5 650-201710001
    vmware esxi 6.5 650-201712001
    vmware esxi 6.5 650-201803001
    vmware esxi 6.5 650-201806001
    vmware esxi 6.5 650-201808001
    vmware esxi 6.0 600-201504401
    vmware esxi 6.0 600-201505401
    vmware esxi 6.0 600-201507101
    vmware esxi 6.0 600-201507102
    vmware esxi 6.0 600-201507401
    vmware esxi 6.0 600-201507402
    vmware esxi 6.0 600-201507403
    vmware esxi 6.0 600-201507404
    vmware esxi 6.0 600-201507405
    vmware esxi 6.0 600-201507406
    vmware esxi 6.0 600-201507407
    vmware esxi 6.0 600-201509101
    vmware esxi 6.0 600-201509102
    vmware esxi 6.0 600-201509201
    vmware esxi 6.0 600-201509202
    vmware esxi 6.0 600-201509203
    vmware esxi 6.0 600-201509204
    vmware esxi 6.0 600-201509205
    vmware esxi 6.0 600-201509206
    vmware esxi 6.0 600-201509207
    vmware esxi 6.0 600-201509208
    vmware esxi 6.0 600-201509209
    vmware esxi 6.0 600-201509210
    vmware esxi 6.0 600-201510401
    vmware esxi 6.0 600-201511401
    vmware esxi 6.0 600-201601101
    vmware esxi 6.0 600-201601102
    vmware esxi 6.0 600-201601402
    vmware esxi 6.0 600-201601403
    vmware esxi 6.0 1
    vmware esxi 6.0 1a
    vmware esxi 6.0 1b
    vmware esxi 6.0 2
    vmware esxi 6.0 3
    vmware esxi 6.0 3a
    vmware esxi 6.0 600-201601401
    vmware esxi 6.0 600-201601404
    vmware esxi 6.0 600-201601405
    vmware esxi 6.0 600-201602401
    vmware esxi 6.0 600-201603101
    vmware esxi 6.0 600-201603102
    vmware esxi 6.0 600-201603201
    vmware esxi 6.0 600-201603202
    vmware esxi 6.0 600-201603203
    vmware esxi 6.0 600-201603204
    vmware esxi 6.0 600-201603205
    vmware esxi 6.0 600-201603206
    vmware esxi 6.0 600-201603207
    vmware esxi 6.0 600-201603208
    vmware esxi 6.0 600-201605401
    vmware esxi 6.0 600-201608101
    vmware esxi 6.0 600-201608401
    vmware esxi 6.0 600-201608402
    vmware esxi 6.0 600-201608403
    vmware esxi 6.0 600-201608404
    vmware esxi 6.0 600-201608405
    vmware esxi 6.0 600-201610410
    vmware esxi 6.0 600-201611401
    vmware esxi 6.0 600-201611402
    vmware esxi 6.0 600-201611403
    vmware esxi 6.0 600-201702101
    vmware esxi 6.0 600-201702102
    vmware esxi 6.0 600-201702201
    vmware esxi 6.0 600-201702202
    vmware esxi 6.0 600-201702203
    vmware esxi 6.0 600-201702204
    vmware esxi 6.0 600-201702205
    vmware esxi 6.0 600-201702206
    vmware esxi 6.0 600-201702207
    vmware esxi 6.0 600-201702208
    vmware esxi 6.0 600-201702209
    vmware esxi 6.0 600-201702210
    vmware esxi 6.0 600-201702211
    vmware esxi 6.0 600-201702212
    vmware esxi 6.0 600-201703401
    vmware esxi 6.0 600-201706101
    vmware esxi 6.0 600-201706102
    vmware esxi 6.0 600-201706103
    vmware esxi 6.0 600-201706401
    vmware esxi 6.0 600-201706402
    vmware esxi 6.0 600-201706403
    vmware esxi 6.0 600-201710301
    vmware esxi 6.0
    vmware esxi 6.5
    vmware workstation 14.0
    vmware fusion 10.0
    vmware esxi 6.7
    ibm pureapplication system 2.2.3.0
    ibm pureapplication system 2.2.3.1
    ibm pureapplication system 2.2.3.2
    ibm pureapplication system 2.2.4.0
    ibm pureapplication system 2.2.5.0
    ibm pureapplication system 2.2.5.1
    ibm pureapplication system 2.2.5.2
    ibm pureapplication system 2.2.5.3