Out-of-Bounds Read Vulnerability in VMware ESXi and Workstation Products
CVE-2020-3981

5.8MEDIUM

Key Information:

Vendor
Vmware
Vendor
CVE Published:
20 October 2020

Summary

An out-of-bounds read vulnerability exists in VMware's ESXi and Workstation products due to a time-of-check time-of-use flaw in the ACPI device. An attacker with administrative access to a virtual machine could exploit this vulnerability to leak sensitive information from the memory of the vmx process. Prompt updates and patches are essential to mitigate potential risks associated with this issue.

Affected Version(s)

VMware ESXi, Workstation, Fusion VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6)

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.