CVE-2018-6982: VMware ESXi

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may lead to an information leak from host to guest.

Affected products

  • VMware ESXi: version 6.0 only; version 6.5 only; version 6.7 only
  • VMware Fusion: from 10.0.0, before 10.1.4 (fixed in 10.1.4); version 11.0.0 only
  • VMware Workstation: from 14.0.0, before 14.1.4 (fixed in 14.1.4); version 15.0.0 only

Published 2018-12-04. Last modified 2026-06-17.