Vulnerability Details CVE-2018-6972
VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi550-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain a denial-of-service vulnerability due to NULL pointer dereference issue in RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.2%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2018-6972
-
cpe:2.3:a:vmware:fusion:10.0
-
cpe:2.3:a:vmware:fusion:10.0.0
-
cpe:2.3:a:vmware:fusion:10.0.1
-
cpe:2.3:a:vmware:fusion:10.1.0
-
cpe:2.3:a:vmware:fusion:10.1.1
-
cpe:2.3:a:vmware:workstation:14.0
-
cpe:2.3:a:vmware:workstation:14.0.0
-
cpe:2.3:a:vmware:workstation:14.1
-
cpe:2.3:a:vmware:workstation:14.1.0
-
cpe:2.3:a:vmware:workstation:14.1.1
-
cpe:2.3:o:apple:mac_os_x:-
-
cpe:2.3:o:vmware:esxi:5.5
-
cpe:2.3:o:vmware:esxi:6.0
-
cpe:2.3:o:vmware:esxi:6.5
-
cpe:2.3:o:vmware:esxi:6.7