Memory leak in VMware ESXi - CVE-2020-3995

 

Memory leak in VMware ESXi - CVE-2020-3995

Published: October 20, 2020


Vulnerability identifier: #VU47751
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3995
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak within the VMCI host driver. A remote attacker can force the application to leak memory and perform denial of service attack.


Affected software

VMware ESXi
VMware Fusion
VMware Workstation
Dell EMC VxRail Appliance

How to mitigate CVE-2020-3995

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi650-202007101-SG, ESXi670-202008101-SG
VMware Fusion - update to 11.1.0
VMware Workstation - update to 15.1.0
Dell EMC VxRail Appliance - addressed in versions 4.5.452, 4.7.525, 7.0.101

External References

Related Security Bulletins