CVE-2018-6977: VMware ESXi

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive.

Affected products

  • VMware ESXi: version 6.0 only; version 6.5 only; version 6.7 only
  • VMware Fusion: from 10.0.0, up to and including 10.1.5; from 11.0.0, up to and including 11.0.2
  • VMware Workstation: from 14.0.0, up to and including 14.1.5; from 15.0.0, up to and including 15.0.2

Published 2018-10-09. Last modified 2026-06-17.