Memory leak in VMware ESXi - CVE-2020-3995
Published: October 20, 2020
Vulnerability identifier: #VU47751
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3995
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak within the VMCI host driver. A remote attacker can force the application to leak memory and perform denial of service attack.
Affected software
VMware ESXi
VMware Fusion
VMware Workstation
Dell EMC VxRail Appliance
VMware Fusion
VMware Workstation
Dell EMC VxRail Appliance
How to mitigate CVE-2020-3995
Install updates from vendor's website.
VMware ESXi - addressed in versions ESXi650-202007101-SG, ESXi670-202008101-SG
VMware Fusion - update to 11.1.0
VMware Workstation - update to 15.1.0
Dell EMC VxRail Appliance - addressed in versions 4.5.452, 4.7.525, 7.0.101
VMware Fusion - update to 11.1.0
VMware Workstation - update to 15.1.0
Dell EMC VxRail Appliance - addressed in versions 4.5.452, 4.7.525, 7.0.101