Executive Summary
Summary | |
---|---|
Title | VMware ESXi, Workstation and Fusion updates address side-channel analysis due to speculative execution. |
Informations | |||
---|---|---|---|
Name | VMSA-2018-0002 | First vendor Publication | 2018-01-03 |
Vendor | VMware | Last vendor Modification | 2018-01-09 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:M/Au:N/C:C/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.7 | Attack Range | Local |
Cvss Impact Score | 6.9 | Attack Complexity | Medium |
Cvss Expoit Score | 3.4 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Bounds Check bypass and Branch Target Injection issues CPU data cache timing can be abused to efficiently leak information out of mis-speculated CPU execution, leading to (at worst) arbitrary virtual memory read vulnerabilities across local security boundaries in various contexts. (Speculative execution is an automatic and inherent CPU performance optimization used in all modern processors.) ESXi, Workstation and Fusion are vulnerable to Bounds Check Bypass and Branch Target Injection issues resulting from this vulnerability. Result of exploitation may allow for information disclosure from one Virtual Machine to another Virtual Machine that is running on the same host. The remediation listed in the table below is for the known variants of the Bounds Check Bypass and Branch Target Injection issues. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifiers CVE-2017-5753 (Bounds Check bypass) and CVE-2017-5715 (Branch Target Injection) to these issues. Column 5 of the following table lists the action required to remediate the observed vulnerability in each release, if a solution is available. |
Original Source
Url : http://www.vmware.com/security/advisories/VMSA-2018-0002.html |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-203 | Information Exposure Through Discrepancy |
CPE : Common Platform Enumeration
Snort® IPS/IDS
Date | Description |
---|---|
2018-02-20 | Intel x64 side-channel analysis information leak attempt RuleID : 45444 - Revision : 2 - Type : OS-OTHER |
2018-02-20 | Intel x64 side-channel analysis information leak attempt RuleID : 45443 - Revision : 2 - Type : OS-OTHER |
2018-02-06 | Intel x64 side-channel analysis information leak attempt RuleID : 45368 - Revision : 2 - Type : OS-OTHER |
2018-02-06 | Intel x64 side-channel analysis information leak attempt RuleID : 45367 - Revision : 2 - Type : OS-OTHER |
2018-02-06 | Intel x86 side-channel analysis information leak attempt RuleID : 45366 - Revision : 2 - Type : OS-OTHER |
2018-02-06 | Intel x86 side-channel analysis information leak attempt RuleID : 45365 - Revision : 2 - Type : OS-OTHER |
2018-02-06 | Intel x86 side-channel analysis information leak attempt RuleID : 45364 - Revision : 2 - Type : OS-OTHER |
2018-02-06 | Intel x86 side-channel analysis information leak attempt RuleID : 45363 - Revision : 2 - Type : OS-OTHER |
2018-02-06 | Intel x86 side-channel analysis information leak attempt RuleID : 45362 - Revision : 2 - Type : OS-OTHER |
2018-02-06 | Intel x86 side-channel analysis information leak attempt RuleID : 45361 - Revision : 2 - Type : OS-OTHER |
2018-02-06 | Intel x86 side-channel analysis information leak attempt RuleID : 45360 - Revision : 2 - Type : OS-OTHER |
2018-02-06 | Intel x86 side-channel analysis information leak attempt RuleID : 45359 - Revision : 2 - Type : OS-OTHER |
2018-02-06 | Intel x86 side-channel analysis information leak attempt RuleID : 45358 - Revision : 2 - Type : OS-OTHER |
2018-02-06 | Intel x86 side-channel analysis information leak attempt RuleID : 45357 - Revision : 2 - Type : OS-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2018-11-02 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL91229003.nasl - Type : ACT_GATHER_INFO |
2018-10-31 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201810-06.nasl - Type : ACT_GATHER_INFO |
2018-09-18 | Name : The remote EulerOS Virtualization host is missing multiple security updates. File : EulerOS_SA-2018-1236.nasl - Type : ACT_GATHER_INFO |
2018-09-18 | Name : The remote EulerOS Virtualization host is missing a security update. File : EulerOS_SA-2018-1233.nasl - Type : ACT_GATHER_INFO |
2018-09-17 | Name : The remote Debian host is missing a security update. File : debian_DLA-1506.nasl - Type : ACT_GATHER_INFO |
2018-09-07 | Name : The remote Debian host is missing a security update. File : debian_DLA-1497.nasl - Type : ACT_GATHER_INFO |
2018-08-17 | Name : The remote PhotonOS host is missing multiple security updates. File : PhotonOS_PHSA-2018-1_0-0098.nasl - Type : ACT_GATHER_INFO |
2018-07-24 | Name : The remote PhotonOS host is missing multiple security updates. File : PhotonOS_PHSA-2018-2_0-0011.nasl - Type : ACT_GATHER_INFO |
2018-07-20 | Name : The remote Debian host is missing a security update. File : debian_DLA-1423.nasl - Type : ACT_GATHER_INFO |
2018-07-16 | Name : The remote Debian host is missing a security update. File : debian_DLA-1422.nasl - Type : ACT_GATHER_INFO |
2018-07-09 | Name : The remote Fedora host is missing a security update. File : fedora_2018-9f02e5ed7b.nasl - Type : ACT_GATHER_INFO |
2018-05-30 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-4213.nasl - Type : ACT_GATHER_INFO |
2018-05-03 | Name : The remote Debian host is missing a security update. File : debian_DLA-1369.nasl - Type : ACT_GATHER_INFO |
2018-05-02 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-4188.nasl - Type : ACT_GATHER_INFO |
2018-05-02 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-4187.nasl - Type : ACT_GATHER_INFO |
2018-04-26 | Name : The remote Debian host is missing a security update. File : debian_DLA-1362.nasl - Type : ACT_GATHER_INFO |
2018-04-25 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-4179.nasl - Type : ACT_GATHER_INFO |
2018-04-18 | Name : The remote Amazon Linux 2 host is missing a security update. File : al2_ALAS-2018-956.nasl - Type : ACT_GATHER_INFO |
2018-04-18 | Name : The remote Amazon Linux 2 host is missing a security update. File : al2_ALAS-2018-939.nasl - Type : ACT_GATHER_INFO |
2018-04-18 | Name : The remote Amazon Linux 2 host is missing a security update. File : al2_ALAS-2018-942.nasl - Type : ACT_GATHER_INFO |
2018-04-18 | Name : The remote Amazon Linux 2 host is missing a security update. File : al2_ALAS-2018-952.nasl - Type : ACT_GATHER_INFO |
2018-04-18 | Name : The remote Amazon Linux 2 host is missing a security update. File : al2_ALAS-2018-953.nasl - Type : ACT_GATHER_INFO |
2018-04-18 | Name : The remote Amazon Linux 2 host is missing a security update. File : al2_ALAS-2018-962.nasl - Type : ACT_GATHER_INFO |
2018-04-17 | Name : The remote Debian host is missing a security update. File : debian_DLA-1349.nasl - Type : ACT_GATHER_INFO |
2018-04-10 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201804-08.nasl - Type : ACT_GATHER_INFO |
2018-03-29 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_1ce95bc7327811e8b52700012e582166.nasl - Type : ACT_GATHER_INFO |
2018-03-15 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_74daa370279711e895eca4badb2f4699.nasl - Type : ACT_GATHER_INFO |
2018-03-15 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2018-0512.nasl - Type : ACT_GATHER_INFO |
2018-02-27 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2018-057-01.nasl - Type : ACT_GATHER_INFO |
2018-02-23 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-4120.nasl - Type : ACT_GATHER_INFO |
2018-02-22 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2018-956.nasl - Type : ACT_GATHER_INFO |
2018-02-07 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2018-037-01.nasl - Type : ACT_GATHER_INFO |
2018-02-05 | Name : The remote Virtuozzo host is missing multiple security updates. File : Virtuozzo_VZA-2018-006.nasl - Type : ACT_GATHER_INFO |
2018-01-30 | Name : A web browser installed on the remote Windows host is affected by multiple se... File : google_chrome_64_0_3282_119.nasl - Type : ACT_GATHER_INFO |
2018-01-26 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2018-0151.nasl - Type : ACT_GATHER_INFO |
2018-01-25 | Name : The remote AIX host is missing a security patch. File : aix_IJ03035.nasl - Type : ACT_GATHER_INFO |
2018-01-25 | Name : The remote AIX host is missing a security patch. File : aix_IJ03036.nasl - Type : ACT_GATHER_INFO |
2018-01-25 | Name : The remote AIX host is missing a security patch. File : aix_IJ03034.nasl - Type : ACT_GATHER_INFO |
2018-01-25 | Name : The remote AIX host is missing a security patch. File : aix_IJ03033.nasl - Type : ACT_GATHER_INFO |
2018-01-25 | Name : The remote AIX host is missing a security patch. File : aix_IJ03032.nasl - Type : ACT_GATHER_INFO |
2018-01-25 | Name : The remote AIX host is missing a security patch. File : aix_IJ03030.nasl - Type : ACT_GATHER_INFO |
2018-01-25 | Name : The remote AIX host is missing a security patch. File : aix_IJ03029.nasl - Type : ACT_GATHER_INFO |
2018-01-19 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1017.nasl - Type : ACT_GATHER_INFO |
2018-01-19 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1014.nasl - Type : ACT_GATHER_INFO |
2018-01-19 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1015.nasl - Type : ACT_GATHER_INFO |
2018-01-19 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1016.nasl - Type : ACT_GATHER_INFO |
2018-01-19 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1020.nasl - Type : ACT_GATHER_INFO |
2018-01-19 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1021.nasl - Type : ACT_GATHER_INFO |
2018-01-19 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2018-942.nasl - Type : ACT_GATHER_INFO |
2018-01-19 | Name : The remote Fedora host is missing a security update. File : fedora_2018-690989736a.nasl - Type : ACT_GATHER_INFO |
2018-01-18 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2018-0094.nasl - Type : ACT_GATHER_INFO |
2018-01-18 | Name : The remote CentOS host is missing a security update. File : centos_RHSA-2018-0093.nasl - Type : ACT_GATHER_INFO |
2018-01-16 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2018-016-01.nasl - Type : ACT_GATHER_INFO |
2018-01-15 | Name : The remote Fedora host is missing a security update. File : fedora_2018-0590e4af13.nasl - Type : ACT_GATHER_INFO |
2018-01-12 | Name : A display driver installed on the remote Linux host is affected by multiple v... File : nvidia_unix_cve_2017_5753.nasl - Type : ACT_GATHER_INFO |
2018-01-12 | Name : A virtualization application installed on the remote macOS or Mac OS X host i... File : macosx_fusion_vmsa_2018_0004.nasl - Type : ACT_GATHER_INFO |
2018-01-12 | Name : A display driver installed on the remote Windows host is affected by multiple... File : nvidia_win_cve_2017_5753.nasl - Type : ACT_GATHER_INFO |
2018-01-09 | Name : A web browser installed on the remote macOS or Mac OS X host is affected by a... File : macosx_Safari11_0_2_patch_2018_01_08.nasl - Type : ACT_GATHER_INFO |
2018-01-09 | Name : The remote Virtuozzo host is missing multiple security updates. File : Virtuozzo_VZA-2018-003.nasl - Type : ACT_GATHER_INFO |
2018-01-09 | Name : The remote EulerOS host is missing multiple security updates. File : EulerOS_SA-2018-1002.nasl - Type : ACT_GATHER_INFO |
2018-01-08 | Name : The remote Virtuozzo host is missing multiple security updates. File : Virtuozzo_VZA-2018-002.nasl - Type : ACT_GATHER_INFO |
2018-01-08 | Name : The remote EulerOS host is missing multiple security updates. File : EulerOS_SA-2018-1001.nasl - Type : ACT_GATHER_INFO |
2018-01-05 | Name : A server virtualization platform installed on the remote host is affected by ... File : citrix_xenserver_CTX231390.nasl - Type : ACT_GATHER_INFO |
2018-01-05 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2018-0007.nasl - Type : ACT_GATHER_INFO |
2018-01-05 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2018-0008.nasl - Type : ACT_GATHER_INFO |
2018-01-05 | Name : The remote CentOS host is missing a security update. File : centos_RHSA-2018-0013.nasl - Type : ACT_GATHER_INFO |
2018-01-05 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2018-0014.nasl - Type : ACT_GATHER_INFO |
2018-01-05 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2018-0023.nasl - Type : ACT_GATHER_INFO |
2018-01-05 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2018-0029.nasl - Type : ACT_GATHER_INFO |
2018-01-05 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2018-0030.nasl - Type : ACT_GATHER_INFO |
2018-01-05 | Name : A web browser installed on the remote macOS or Mac OS X host is affected by a... File : macosx_firefox_57_0_4.nasl - Type : ACT_GATHER_INFO |
2018-01-05 | Name : A web browser installed on the remote Windows host is affected by a speculati... File : mozilla_firefox_57_0_4.nasl - Type : ACT_GATHER_INFO |
2018-01-04 | Name : The remote CentOS host is missing a security update. File : centos_RHSA-2018-0012.nasl - Type : ACT_GATHER_INFO |
2018-01-04 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2018-939.nasl - Type : ACT_GATHER_INFO |
2017-12-29 | Name : A virtualization application installed on the remote macOS or Mac OS X host i... File : macosx_fusion_vmsa_2017_0021.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2018-01-09 21:21:50 |
|
2018-01-06 09:23:38 |
|
2018-01-04 05:19:15 |
|