Memory leak in VMware, Inc products - CVE-2020-3959
Published: May 29, 2020
Vulnerability identifier: #VU28339
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3959
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform denial of service (DoS) attack on the target system.
The vulnerability exists due memory leak in the VMCI module. A local user can force the application to leak memory and perform denial of service attack.
Affected software
VMware ESXi
VMware Fusion
VMware Workstation
PowerFlex rack
VMware Fusion
VMware Workstation
PowerFlex rack
How to mitigate CVE-2020-3959
Install updates from vendor's website.
VMware ESXi - addressed in versions ESXi650-202005401-SG, ESXi670-202004101-SG
VMware Fusion - update to 11.1.0
VMware Workstation - update to 15.1.0
PowerFlex rack - addressed in versions 3.3.8.1, 3.4.3.1, 3.5.3.1
VMware Fusion - update to 11.1.0
VMware Workstation - update to 15.1.0
PowerFlex rack - addressed in versions 3.3.8.1, 3.4.3.1, 3.5.3.1