Heap Overflow Vulnerability in VMware ESXi, Workstation, and Fusion
CVE-2020-3967
What is CVE-2020-3967?
VMware ESXi, Workstation, and Fusion are susceptible to a heap overflow vulnerability in the USB 2.0 controller (EHCI). This vulnerability allows a malicious actor with local access to a virtual machine to potentially execute code on the hypervisor. For the exploit to be successful, additional conditions must be present beyond the attacker's control, making it a complex scenario for unauthorized code execution. IT administrators should prioritize patching and securing their VMware products as indicated in the official advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fusion 11.x before 11.5.5
VMware ESXi 7.0 before ESXi_7.0.0-1.20.16321839
VMware ESXi 6.7 before ESXi670-202004101-SG
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved