Site icon Davoud Teimouri – Virtualization and Data Center

[News]: VMware Tools HGFS Vulnerability

security advisory

VMware Tools HGFS Out-Of-Bounds Read Vulnerability

VMware Tools contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on guest VMs.

Note: In order to be able to exploit this issue, file sharing must be enabled.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2018-6969 to this issue.

VMware Tools must be updated to 10.3.0 for each Windows VM to resolve CVE-2018-6969. The new version is available at the below link:

VMware Tools 10.3.0

It’s recommended that upgrade VMware Tools if you have enabled sharing but I think, it’s better upgrade VMware Tools anyway.

Other resolved issues in this release are as follows:

More on Teimouri.Net

[Script]: Check Time Synchronization with Host on Virtual Machines – PowerCLI

VMware Tools Client – Interact with a VM without Network Connectivity

Java.net.SocketException: No buffer space available – VMware View Connection Server

Update VMware Tools Automatically

[PowerCLI]: Change Local Account Password on ESXi

[Review]: VMware Tools 10.2.0

Exit mobile version