Saturday, March 17, 2018

VMware Denial-of-Service Vulnerability

There has been found a denial-of-service vulnerability (CVE-2018-6957) in VMware virtualization applications. The vulnerability can be triggered by opening a large number of VNC sessions. This is only possible if VNC is manually enabled.

Affected versions:
- VMware Workstation Pro / Player 14.x versions earlier than 14.1.1
- VMware Workstation Pro / Player 12.x versions, mitigation
- VMware Fusion Pro / Fusion 10.x versions earlier than 10.1.1
- VMware Fusion Pro / Fusion 8.x versions, mitigation

Further information including updating instructions can be read from VMware's security advisory.

No comments: