Vulnerability Spotlight: VMWare Workstation DoS Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-6965 | VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6966 and CVE-2018-6967. NVD description · AI analysis pending | 8.1 | 3% |
| — |
Full article211 words · extracted from blog.talosintelligence.com · click to collapse
Friday, June 29, 2018 10:28
Discovered by a member of Cisco Talos.Today, Talos is disclosing a vulnerability in VMWare Workstation that could result in Denial of Service. VMWare Workstation is a widely used virtualization platform designed to run alongside a normal operating system, allowing users to use both virtualized and physical systems concurrently.
TALOS-2018-0540
TALOS-2018-0540 / CVE-2018-6965 is an exploitable Denial of Service (DoS) vulnerability in the VMWare Workstation 14 software. The vulnerability lies in the pixel shader utilized by VMWare Workstation and can be triggered by supplying a malformed pixel shader in either text or binary form inside a VMWare guest operating system. This vulnerability can be triggered from VMWare guest or VMWare hosts and results in a process crashing leading to a DoS state.
For more technical details, please read our advisory here.
Tested Software:
VMware Workstation 14 (14.1.1.28517)
Coverage
Talos has developed the following Snort rules to detect attempts to exploit this vulnerability. Note that these rules are subject to change pending additional vulnerability information. For the most current information, please visit your Firepower Management Center or Snort.org.
Snort Rules: 45981-45982
For other vulnerabilities Talos has disclosed, please refer to our Vulnerability Report Portal: http://www.talosintelligence.com/vulnerability-reports/
To review our Vulnerability Disclosure Policy, please visit this site:
http://www.cisco.com/c/en/us/about/security-center/vendor-vulnerability-policy.html
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/vmware-dos-vulnerability/