CVE-2018-6974: VMware ESXi

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds read vulnerability in SVGA device. This issue may allow a guest to execute code on the host.

Affected products

  • VMware ESXi: version 6.0 only; version 6.5 only; version 6.7 only
  • VMware Fusion: from 10.0, before 10.1.3 (fixed in 10.1.3)
  • VMware Workstation: from 14.0, before 14.1.3 (fixed in 14.1.3)

Published 2018-10-16. Last modified 2026-06-17.