Reachable Assertion in VMware, Inc products - CVE-2020-3958
Published: May 29, 2020 / Updated: June 1, 2020
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to reachable assertion in the shader functionality. A remote user of guest operating system can
pass a malformed pixel shader (inside VMware guest OS) and perform a denial of
service (DoS) attack due a panic condition in the vmware-vmx.exe process on host.
Affected software
VMware Fusion
VMware Workstation
How to mitigate CVE-2020-3958
VMware Fusion - update to 11.5.2
VMware Workstation - update to 15.5.2