5.3

CVE-2018-6957

VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled.

Data is provided by the National Vulnerability Database (NVD)
VMwareWorkstation Pro Version >= 14.0 < 14.1.1
VMwareWorkstation Pro Version12.0
VMwareWorkstation Pro Version12.1
VMwareWorkstation Pro Version12.01
VMwareWorkstation Pro Version12.1.1
VMwareWorkstation Pro Version12.5
VMwareWorkstation Pro Version12.5.1
VMwareWorkstation Pro Version12.5.2
VMwareWorkstation Pro Version12.5.3
VMwareWorkstation Pro Version12.5.4
VMwareWorkstation Pro Version12.5.5
VMwareWorkstation Pro Version12.5.6
VMwareWorkstation Pro Version12.5.7
VMwareWorkstation Player Version >= 14.0 < 14.1.1
VMwareWorkstation Player Version12.0
VMwareWorkstation Player Version12.0.1
VMwareWorkstation Player Version12.1
VMwareWorkstation Player Version12.1.1
VMwareWorkstation Player Version12.5
VMwareWorkstation Player Version12.5.1
VMwareWorkstation Player Version12.5.2
VMwareWorkstation Player Version12.5.3
VMwareWorkstation Player Version12.5.4
VMwareWorkstation Player Version12.5.5
VMwareWorkstation Player Version12.5.6
VMwareWorkstation Player Version12.5.7
VMwareFusion Version8.0
VMwareFusion Version8.0.1
VMwareFusion Version8.0.2
VMwareFusion Version8.1
VMwareFusion Version8.1.1
VMwareFusion Version8.5
VMwareFusion Version8.5.1
VMwareFusion Version8.5.2
VMwareFusion Version8.5.3
VMwareFusion Version8.5.4
VMwareFusion Version8.5.5
VMwareFusion Version8.5.6
VMwareFusion Version8.5.7
VMwareFusion Version8.5.8
VMwareFusion Version >= 10.0 < 10.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.38% 0.586
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 1.6 3.6
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:N/A:P
CWE-772 Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.