Use-After-Free Vulnerability in VMware ESXi, Workstation, and Fusion
CVE-2020-4004
What is CVE-2020-4004?
A use-after-free vulnerability exists in the XHCI USB controller of VMware products, allowing attackers with local administrative privileges on a virtual machine to execute arbitrary code in the context of the VMX process on the host. This could lead to unauthorized actions within the virtual machine environment, posing a significant security risk to affected VMware installations. Proper updates and patches are required to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fusion 11.x before 11.5.7
VMware ESXi 7.0 before ESXi70U1b-17168206
VMware ESXi 6.7 before ESXi670-202011101-SG
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved