Out-of-bounds read in VMware, Inc products - CVE-2020-3970
Published: June 25, 2020 / Updated: July 1, 2020
Vulnerability identifier: #VU29296
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3970
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in the Shader functionality. A local attacker can trigger out-of-bounds read error and cause a denial of service condition on the system.
Affected software
Cloud Foundation
VMware Fusion
VMware Workstation
VMware ESXi
EMC Integrated Data Protection Appliance
VMware Fusion
VMware Workstation
VMware ESXi
EMC Integrated Data Protection Appliance
How to mitigate CVE-2020-3970
Install updates from vendor's website.
Cloud Foundation - update to 3.10
VMware ESXi - addressed in versions ESXi_7.0.0-1.20.16321839, ESXi650-202005401-SG, ESXi670-202004101-SG
VMware Fusion - update to 11.5.5
VMware Workstation - update to 15.5.5
EMC Integrated Data Protection Appliance - update to 2.6.0
VMware ESXi - addressed in versions ESXi_7.0.0-1.20.16321839, ESXi650-202005401-SG, ESXi670-202004101-SG
VMware Fusion - update to 11.5.5
VMware Workstation - update to 15.5.5
EMC Integrated Data Protection Appliance - update to 2.6.0