{"api_version":"1","generated_at":"2026-05-11T07:27:54+00:00","cve":"CVE-2018-6963","urls":{"html":"https://cve.report/CVE-2018-6963","api":"https://cve.report/api/cve/CVE-2018-6963.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-6963","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-6963"},"summary":{"title":"CVE-2018-6963","description":"VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabilities that occur due to NULL pointer dereference issues in the RPC handler. Successful exploitation of these issues may allow an attacker with limited privileges on the guest machine trigger a denial-of-Service of their guest machine.","state":"PUBLIC","assigner":"security@vmware.com","published_at":"2018-05-22 13:29:00","updated_at":"2018-06-26 18:23:00"},"problem_types":["CWE-476"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/104237","name":"104237","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"VMware Workstation and Fusion CVE-2018-6963 Multiple Denial of Service Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1040957","name":"1040957","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"VMware Workstation and Fusion Flaws Let Local Users Deny Service and Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.vmware.com/security/advisories/VMSA-2018-0013.html","name":"https://www.vmware.com/security/advisories/VMSA-2018-0013.html","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"VMSA-2018-0013","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-6963","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-6963","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"6963","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"fusion","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"6963","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"fusion","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"6963","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"workstation","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"6963","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"workstation","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@vmware.com","DATE_PUBLIC":"2018-05-21T00:00:00","ID":"CVE-2018-6963","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Workstation","version":{"version_data":[{"version_value":"14.x before 14.1.2"}]}},{"product_name":"Fusion","version":{"version_data":[{"version_value":"10.x before 10.1.2"}]}}]},"vendor_name":"VMware"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabilities that occur due to NULL pointer dereference issues in the RPC handler. Successful exploitation of these issues may allow an attacker with limited privileges on the guest machine trigger a denial-of-Service of their guest machine."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Multiple Denial-of-service vulnerabilities"}]}]},"references":{"reference_data":[{"name":"104237","refsource":"BID","url":"http://www.securityfocus.com/bid/104237"},{"name":"1040957","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1040957"},{"name":"https://www.vmware.com/security/advisories/VMSA-2018-0013.html","refsource":"CONFIRM","url":"https://www.vmware.com/security/advisories/VMSA-2018-0013.html"}]}},"nvd":{"publishedDate":"2018-05-22 13:29:00","lastModifiedDate":"2018-06-26 18:23:00","problem_types":["CWE-476"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*","versionStartIncluding":"14.0","versionEndExcluding":"14.1.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"10.1.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"6963","Ordinal":"123197","Title":"CVE-2018-6963","CVE":"CVE-2018-6963","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"6963","Ordinal":"1","NoteData":"VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabilities that occur due to NULL pointer dereference issues in the RPC handler. Successful exploitation of these issues may allow an attacker with limited privileges on the guest machine trigger a denial-of-Service of their guest machine.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"6963","Ordinal":"2","NoteData":"2018-05-22","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"6963","Ordinal":"3","NoteData":"2018-05-23","Type":"Other","Title":"Modified"}]}}}