CVE-2018-6983 is an integer overflow vulnerability affecting VMware Workstation (versions 15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (versions 11.x before 11.0.2 and 10.x before 10.1.5) within their virtual network devices. This flaw carries a high CVSS score of 8.8, indicating that a low-privileged guest user could achieve host-level code execution with low attack complexity. While not listed in CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage, including a SecurityWeek article, though no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 14.0.0, < 14.1.5CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | ||
>= 15.0.0, < 15.0.2CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.1.5CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.0.2CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.