Vmware · Vmware Fusion · CVE-2020-3969
**Name of the Vulnerable Software and Affected Versions**
VMware ESXi versions 7.0 before ESXi 7.0.0-1.20.16321839
VMware ESXi versions 6.7 before ESXi670-202004101-SG
VMware ESXi versions 6.5 before ESXi650-202005401-SG
VMware Workstation versions 15.x before 15.5.5
VMware Fusion versions 11.x before 11.5.5
**Description**
The issue is related to an off-by-one heap-overflow vulnerability in the SVGA device, which can be exploited by a malicious actor with local access to a virtual machine with 3D graphics enabled, potentially allowing code execution on the hypervisor from a virtual machine. Exploitation requires additional conditions beyond the attacker's control. The vulnerability is also described as a buffer overflow in dynamic memory when processing SVGA3D commands.
**Recommendations**
For VMware ESXi versions 7.0 before ESXi 7.0.0-1.20.16321839, update to a version that includes the fix ESXi 7.0.0-1.20.16321839 or later.
For VMware ESXi versions 6.7 before ESXi670-202004101-SG, apply the patch ESXi670-202004101-SG or later.
For VMware ESXi versions 6.5 before ESXi650-202005401-SG, apply the patch ESXi650-202005401-SG or later.
For VMware Workstation versions 15.x before 15.5.5, update to version 15.5.5 or later.
For VMware Fusion versions 11.x before 11.5.5, update to version 11.5.5 or later.