CVE-2020-3947: Use After Free
VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition of the vmnetdhcp service running on the host machine.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-3947?
CVE-2020-3947 is a use-after vulnerability in vmnetdhcp in VMware Workstation and Fusion.
What is the severity of CVE-2020-3947?
CVE-2020-3947 has a severity score of 8.8, which is considered high.
What versions of VMware Workstation and Fusion are affected by CVE-2020-3947?
VMware Workstation versions between 15.0.0 and 15.5.2, and Fusion versions between 11.0.0 and 11.5.2 are affected by CVE-2020-3947.
How can CVE-2020-3947 be exploited?
Successful exploitation of CVE-2020-3947 may lead to code execution on the host from the guest, or allow attackers to create a denial-of-service condition of the vmnetdhcp service.
Where can I find more information about CVE-2020-3947?
You can find more information about CVE-2020-3947 in the VMware Security Advisory VMSA-2020-0004.