PT-2020-5285 · Vmware · Vmware Fusion+3

Published

2020-12-18

·

Updated

2025-08-08

·

CVE-2020-3999

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions VMware ESXi versions 7.0 prior to ESXi70U1c-17325551 VMware Workstation versions 16.x prior to 16.0 and 15.x prior to 15.5.7 VMware Fusion versions 12.x prior to 12.0 and 11.x prior to 11.5.7 VMware Cloud Foundation (affected versions not specified)
Description The issue is related to a denial of service vulnerability due to improper input validation in GuestInfo. A malicious actor with normal user privilege access to a virtual machine can crash the virtual machine's vmx process, leading to a denial of service condition. This can be caused by a null pointer dereference.
Recommendations For VMware ESXi versions 7.0 prior to ESXi70U1c-17325551, update to ESXi70U1c-17325551 or later. For VMware Workstation versions 16.x prior to 16.0, update to 16.0 or later. For VMware Workstation versions 15.x prior to 15.5.7, update to 15.5.7 or later. For VMware Fusion versions 12.x prior to 12.0, update to 12.0 or later. For VMware Fusion versions 11.x prior to 11.5.7, update to 11.5.7 or later. As a temporary workaround, consider restricting access to the GuestInfo interface until a patch is available.

Fix

DoS

NULL Pointer Dereference

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-00015
CVE-2020-3999
ZDI-20-1450

Affected Products

Vmware Cloud Foundation
Vmware Esxi
Vmware Fusion
Vmware Workstation