CVE-2018-6972: VMware ESXi

Medium severity, CVSS 6.5. EPSS: 3% chance of exploitation in the next 30 days.

VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi550-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain a denial-of-service vulnerability due to NULL pointer dereference issue in RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

Affected products

  • VMware ESXi: version 5.5 only; version 6.0 only; version 6.5 only; version 6.7 only
  • VMware Fusion: from 10.0, before 10.1.2 (fixed in 10.1.2)
  • VMware Workstation: from 14.0, before 14.1.2 (fixed in 14.1.2)

Published 2018-07-25. Last modified 2026-06-17.