CVE-2018-6957

VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled.
References
Link Resource
http://www.securityfocus.com/bid/103431 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040539 Third Party Advisory VDB Entry
https://www.vmware.com/security/advisories/VMSA-2018-0008.html Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:workstation_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.01:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.1.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.5.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.5.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.5.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.5.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.5.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.5.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_pro:12.5.7:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:vmware:workstation_player:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.1.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.5.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.5.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.5.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.5.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.5.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.5.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation_player:12.5.7:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:vmware:fusion:8.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.1.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.5.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.5.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.5.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.5.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.5.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.5.6:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.5.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:fusion:8.5.8:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-03-15 19:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-6957

Mitre link : CVE-2018-6957

CVE.ORG link : CVE-2018-6957


JSON object : View

Products Affected

vmware

  • fusion
  • workstation_pro
  • workstation_player
CWE
CWE-772

Missing Release of Resource after Effective Lifetime

NVD-CWE-noinfo