Use-after-free in VMware Fusion and VMware Workstation - CVE-2020-3947

 

Use-after-free in VMware Fusion and VMware Workstation - CVE-2020-3947

Published: March 13, 2020 / Updated: March 13, 2020


Vulnerability identifier: #VU26073
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3947
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in vmnetdhcp. A local attacker can execute arbitrary code on the host from the guest or cause a denial-of-service condition of the vmnetdhcp service running on the host machine.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

VMware Fusion
VMware Workstation

How to mitigate CVE-2020-3947

Install updates from vendor's website.

VMware Fusion - update to 11.5.2
VMware Workstation - update to 15.5.2

External References

Related Security Bulletins