---
title: "VMware response on recent Security issues - Specter & Meltdown"
canonical: "https://www.virtcloudrocks.com/space/vblog01/blog/720986/VMware%20response%20on%20recent%20Security%20issues%20-%20Specter%20%26%20Meltdown"
format: markdown
---
I would like to share with you VMware Security team’s response over the security issues identified as **CVE-2017-5753, CVE-2017-5715 (Specter),** and **CVE-2017-5754 (Meltdown)** which have been disclosed in multiple locations: 

[https://spectreattack.com/](https://spectreattack.com/)  
[https://meltdownattack.com/](https://meltdownattack.com/)

 

***Meltdown (CVE-2017-5754) does not affect ESXi***, Workstation, and Fusion because ESXi does not run untrusted user mode code, and Workstation and Fusion rely on the protection that the underlying operating system provides.

OS vendors have begun issuing patches that address CVE-2017-5753, CVE-2017-5715, and CVE-2017-5754 for their operating systems. For these patches to be fully functional in a guest OS additional ESXi updates will be required. 

On 5th of January, 2018, VMware released the following new security advisory which provides the detailed information on the remediation available:

[VMSA-2018-0002 : VMware ESXi, Workstation and Fusion updates address side-channel analysis due to speculative execution](https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html).

 

This advisory documents remediation for known variants of the Bounds-Check Bypass (CVE-2017-5753) and Branch Target Injection (CVE-2017-5715) issues due to speculative execution disclosed today by Google Project Zero. These issues may result in information disclosure from one Virtual Machine to another Virtual Machine that is running on the same host.

 

A third issue due to speculative execution, Rogue Data Cache Load (CVE-2017-5754), was disclosed along the other two issues. It does not affect ESXi, Workstation, and Fusion because ESXi does not run untrusted user mode code, and Workstation and Fusion rely on the protection that the underlying operating system provides.

 

VMware ESXi 6.5 & ESXi 6.0 are already patched against these vulnerabilities by a security patch released earlier – please make sure that you have this security patch applied , refer to below table.

VMware ESXi 5.5 is patched against CVE-2017-5715, but not against CVE-2017-5753 at this time.

  


![image](media://cb8572f6-e6d6-4f16-b5c9-71d8aa9b597e)

Details for these security patches are published in below KB articles :

 

**ESXi 6.5** : Remediated by ESXi 6.5 Patch 2 released on 19 Dec , 2017 -  [KB 2151099](http://kb.vmware.com/kb/2151099)  


**ESXi 6.0** : Remediated by ESXi 6.0 Patch 6 released on 9 Nov , 2017 – [KB 2151132](http://kb.vmware.com/kb/2151132)

**ESXi 5.5** : Remediated for CVE-[2017-5715 ](#)by ESXi 5.5 Patch 11 released 14 Sep , 2017  – [KB 2150876](http://kb.vmware.com/kb/2150876)

 

You may download these patches from : [https://my.vmware.com/group/vmware/patch](https://my.vmware.com/group/vmware/patch)