The VMware Security Engineering, Communications, and Response group (vSECR) has investigated the impact CVE-2018-3620 may have on VMware products. This issue is classified as a Speculative-Execution vulnerability which requires Operating System-Specific Mitigations which are defined in KB55636.
Please sign up at our Security-Announce mailing list to receive new and updated VMware Security Advisories and click Subscribe to Article in the Actions box to be alerted when new information is added to this document.
Evaluation Summary:
Unaffected Products
vSECR has completed evaluation of the following products and determined that under supported configurations they are not affected as there is no available path to execute arbitrary code without administrative privileges.
Note: Automated vulnerability scanners may report that these products are vulnerable to CVE-2018-3620 even though the issue is not exploitable. These products will still be updating their respective kernels in scheduled maintenance releases as a precautionary measure.
If a specific version number is not listed, then that entry refers to all supported versions of the appliance.
Products | Version | Evaluation | Workaround |
VMware App Defense Appliance | Any | Unaffected | N/A |
VMware Horizon DaaS Platform | Any | Unaffected | N/A |
VMware Horizon Mirage | Any | Unaffected | N/A |
VMware HCX | Any | Unaffected | N/A |
VMware Integrated Openstack | Any | Unaffected | N/A |
VMware IoT Pulse | Any | Unaffected | N/A |
VMware Mirage | Any | Unaffected | N/A |
VMware NSX for vSphere | Any | Unaffected | N/A |
VMware NSX-T | Any | Unaffected | N/A |
VMware Skyline Appliance | Any | Unaffected | N/A |
VMware Unified Access Gateway | Any | Unaffected | N/A |
VMware vCenter Server | 5.5 | Unaffected | N/A |
VMware vCloud Availability for vCloud Director | Any | Unaffected | N/A |
VMware vCloud Director Extender | Any | Unaffected | N/A |
VMware vRealize Business for Cloud | Any | Unaffected | N/A |
VMware vRealize Log Insight | Any | Unaffected | N/A |
VMware vRealize Network Insight | Any | Unaffected | N/A |
VMware vRealize Operations | Any | Unaffected | N/A |
VMware vRealize Orchestrator | Any | Unaffected | N/A |
VMware vSphere Replication | Any | Unaffected | N/A |
VMware Workbench | Any | Unaffected | N/A |
Potentially Affected Products
Information on potentially affected products including applicable workarounds can be found in VMSA-2018-0021.