CVE-2018-6981: VMware ESXi

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 or below contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may allow a guest to execute code on the host.

Affected products

  • VMware ESXi: version 6.0 only; version 6.5 only; version 6.7 only
  • VMware Fusion: from 10.0.0, before 10.1.4 (fixed in 10.1.4); version 11.0.0 only
  • VMware Workstation: from 14.0.0, before 14.1.4 (fixed in 14.1.4); version 15.0.0 only

Published 2018-12-04. Last modified 2026-06-17.