Описание
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition on their own VM.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 15.0.0 (включая) до 15.5.1 (исключая)
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*
Конфигурация 2Версия от 11.0.0 (включая) до 11.5.1 (исключая)
Одновременно
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
EPSS
Процентиль: 73%
0.00744
Низкий
9.1 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-787
Связанные уязвимости
github
больше 3 лет назад
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition on their own VM.
EPSS
Процентиль: 73%
0.00744
Низкий
9.1 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-787