CVE-2020-3960: High severity vmware fusion vulnerability
VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrative access to a virtual machine with a virtual NVMe controller present may be able to read privileged information contained in physical memory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-3960.
What is the severity of CVE-2020-3960?
The severity of CVE-2020-3960 is high.
Which software versions are affected by CVE-2020-3960?
VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) are affected by CVE-2020-3960.
What is the CWE ID for CVE-2020-3960?
The CWE ID for CVE-2020-3960 is 125.
How can I fix CVE-2020-3960?
To fix CVE-2020-3960, you should update VMware ESXi to version ESXi670-202006401-SG or later for 6.7, and ESXi650-202005401-SG or later for 6.5. For Workstation, update to version 15.5.5 or later, and for Fusion, update to version 11.5.5 or later.