VMware has published a security advisory to address an out-of-bounds read vulnerability in VMware vSphere ESXi (ESXi) version 6.0, 6.5 and 6.7, VMware Workstation version 14.x and VMWare Fusion version 10.x.
Successful exploitation of the vulnerabilities could allow a guest to execute code on the host.
The product vendor has released new versions to address the issue at the vendor's website:
System administrators may contact their product support vendors for the fixes and assistance.
https://www.vmware.com/security/advisories/VMSA-2018-0026.html
https://www.us-cert.gov/ncas/current-activity/2018/10/16/VMware-Releases-Security-Updates
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6974