First published: Mon Mar 16 2020(Updated: )
VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition of the vmnetdhcp service running on the host machine.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Fusion Pro | >11.0.0<11.5.2 | |
VMware Workstation | >=15.0.0<15.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3947 is a use-after vulnerability in vmnetdhcp in VMware Workstation and Fusion.
CVE-2020-3947 has a severity score of 8.8, which is considered high.
VMware Workstation versions between 15.0.0 and 15.5.2, and Fusion versions between 11.0.0 and 11.5.2 are affected by CVE-2020-3947.
Successful exploitation of CVE-2020-3947 may lead to code execution on the host from the guest, or allow attackers to create a denial-of-service condition of the vmnetdhcp service.
You can find more information about CVE-2020-3947 in the VMware Security Advisory VMSA-2020-0004.