CVE-2018-6965 is an out-of-bounds read vulnerability in the shader translator of VMware ESXi (6.7 prior to ESXi670-201806401-BG), Workstation (14.x prior to 14.1.2), and Fusion (10.x prior to 10.1.2). This high-severity vulnerability (CVSS 8.1) allows attackers with normal user privileges to achieve information disclosure or crash virtual machines. While it has garnered some community discussion and media coverage, there is no evidence of active exploitation, nor is public exploit code available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 14.0, < 14.1.2CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | ||
6.7CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.7:-:*:*:*:*:*:* | ||
6.7CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.7:670-201806001:*:*:*:*:*:* | ||
>= 10.0, < 10.1.2CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.