Back to search
CVE-2020-3963
Published: Jun 25, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with local access to a virtual machine may be able to read privileged information contained in physical memory.
| Vendor | Product | Versions |
|---|---|---|
VMware | VMware ESXi | affected 7.0 before ESXi_7.0.0-1.20.16321839affected 6.7 before ESXi670-202006401-SGaffected 6.5 before ESXi650-202005401-SG |
VMware | Workstation | affected 15.x before 15.5.2 |
VMware | Fusion | affected 11.x before 11.5.2 |
References
https://www.vmware.com/security/advisories/VMSA-2020-0015.html
x_refsource_CONFIRM
20200717 VMware ESXi: Multiple vulnerabilities [CVE-2020-3963, CVE-2020-3964, CVE-2020-3965, CVE-2020-3960]
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now