CVE-2020-3999: Input Validation
VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper input validation in GuestInfo. A malicious actor with normal user privilege access to a virtual machine can crash the virtual machine's vmx process leading to a denial of service condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-3999.
What is the severity of CVE-2020-3999?
The severity of CVE-2020-3999 is medium with a severity value of 6.5.
Which software products are affected by CVE-2020-3999?
VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) are affected by CVE-2020-3999.
What is the vulnerability in GuestInfo?
The vulnerability in CVE-2020-3999 is a denial of service vulnerability due to improper input validation in GuestInfo.
How can I fix the vulnerability CVE-2020-3999?
To fix the vulnerability CVE-2020-3999, it is recommended to update VMware ESXi to version ESXi70U1c-17325551, VMware Workstation to version 16.0 or later, VMware Fusion to version 12.0 or later, or apply the necessary patches provided by VMware.