CVE-2018-6966: VMware ESXi

High severity, CVSS 8.1. EPSS: 2.2% chance of exploitation in the next 30 days.

VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs, a different vulnerability than CVE-2018-6965 and CVE-2018-6967.

Affected products

  • VMware ESXi: version 6.7 only
  • VMware Fusion: from 10.0, before 10.1.2 (fixed in 10.1.2)
  • VMware Workstation: from 14.0, before 14.1.2 (fixed in 14.1.2)

Published 2018-07-09. Last modified 2026-06-17.