VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds read vulnerability
Published Apr 15, 2019
5.9
MEDIUMCVSS 3.0
EPSS 1.04%
Description
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds read vulnerability. Exploitation of this issue requires an attacker to have access to a virtual machine with 3D graphics enabled. Successful exploitation of this issue may lead to information disclosure.The workaround for this issue involves disabling the 3D-acceleration feature. This feature is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.
Affected products
-
Affected
- 6.5 before ESXi650-201903001
- 6.7 before ESXi670-201904101-SG
-
Affected
- 10.x before 10.1.6
- 11.x before 11.0.3
-
Affected
- 14.x before 14.1.6
- 15.x before 15.0.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 10.0.0 · < 10.1.6
- ≥ 11.0.0 · < 11.0.3
- ≥ 14.0.0 · < 14.1.6
- ≥ 15.0.0 · < 15.0.3
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
- 6.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-15095 Advisory
- https://www.vmware.com/security/advisories/VMSA-2019-0006.html x_refsource_CONFIRMPatchVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-19-369/ x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-15095 | Advisory | |
| https://www.vmware.com/security/advisories/VMSA-2019-0006.html | x_refsource_CONFIRMPatchVendor Advisory | |
| https://www.zerodayinitiative.com/advisories/ZDI-19-369/ | x_refsource_MISC |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data