CVE-2020-3947
published 2020-03-16CVE-2020-3947: VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitation of this issue…
PriorityP343high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.64%
46.4th percentile
VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition of the vmnetdhcp service running on the host machine.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | fusion | < 11.5.2 | 11.5.2 |
| vmware | fusion | — | — |
| vmware | workstation | — | — |
| vmware | workstation | >= 15.0.0 < 15.5.2 | 15.5.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Horizon Client, VMRC, VMware Workstation and Fusion updates address use-after-free and privilege escalation vulnerabilities (CVE-2019-5543, CVE-2020-3947, CVE-2020-3948)
vendor_vmware·2020-03-12·CVSS 7.8
CVE-2019-5543 [HIGH] VMware Horizon Client, VMRC, VMware Workstation and Fusion updates address use-after-free and privilege escalation vulnerabilities (CVE-2019-5543, CVE-2020-3947, CVE-2020-3948)
VMSA-2020-0004: VMware Horizon Client, VMRC, VMware Workstation and Fusion updates address use-after-free and privilege escalation vulnerabilities (CVE-2019-5543, CVE-2020-3947, CVE-2020-3948)
VMware Workstation and Fusion contain a use-after vulnerability in vmnetdhcp.VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3.
CVEs: CVE-2019-5543, CVE-2020-3947, CVE-2020-3948
Affected products: ESXi, Fusion Pro, Horizon Client, VMware Fusion, VMware Horizon, VMware Workstation, VMware vSphere, Workstation Player, Workstation Pro
GHSA
GHSA-mxvf-68x6-jqvh: VMware Workstation (15
ghsa_unreviewed·2022-05-24
CVE-2020-3947 [HIGH] GHSA-mxvf-68x6-jqvh: VMware Workstation (15
VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition of the vmnetdhcp service running on the host machine.
No detection rules found.
No public exploits indexed.
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
# Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative
2022/07/27
Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service, VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c. In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/IP s
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
## Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative 2022/07/27 Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service , VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c . In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/IP
Trendmicro
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
blogs_trendmicro·2022-07-27
Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
## Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack
Learn about the patch gap vulnerabilities in the VMware ESXi TCP/IP stack.
By: Zero Day Initiative Jul 27, 2022 Read time: ( words)
Save to Folio
Over the last few years, multiple VMware ESXi remote, unauthenticated code execution vulnerabilities have been publicly disclosed. Some were also found to be exploited in the wild. Since these bugs were found in ESXi’s implementation of the SLP service , VMware provided workarounds to turn off the service. VMware also disabled the service by default starting with ESX 7.0 Update 2c . In this blog post, we explore another remotely reachable attack surface: ESXi’s TCP/IP stack implemented as a VMkernel module. The most interesting outcome of this analysis is that ESXi’s TCP/
Trendmicro
Vulnerability in the VMware Workstation
blogs_trendmicro·2020-04-02·CVSS 8.8
CVE-2020-3947 [HIGH] Vulnerability in the VMware Workstation
# CVE-2020-3947: Use-After-Free Vulnerability in the VMware Workstation DHCP Component
Learn about the vulnerability in the VMware workstation.
By: Zero Day Initiative
2020/04/02
Read time: ( words)
Save to Folio
Ever since introducing the virtualization category at Pwn2Own in 2016, guest-to-host escapes have been a highlight of the contest. This year’s event was no exception. Other guest-to-host escapes have also come through the ZDI program throughout the year. In fact, VMware released a patch for just such a bug less than a week prior to this year’s competition. In this blog post, we look into CVE-2020-3947, which was submitted to the ZDI program (ZDI-20-298) in late December by an anonymous researcher. The vulnerability affects the DHCP server component of VMware Workstation and c
Trendmicro
Vulnerability in the VMware Workstation
blogs_trendmicro·2020-04-02·CVSS 8.8
CVE-2020-3947 [HIGH] Vulnerability in the VMware Workstation
## CVE-2020-3947: Use-After-Free Vulnerability in the VMware Workstation DHCP Component
Learn about the vulnerability in the VMware workstation.
By: Zero Day Initiative Apr 02, 2020 Read time: ( words)
Save to Folio
Ever since introducing the virtualization category at Pwn2Own in 2016, guest-to-host escapes have been a highlight of the contest. This year’s event was no exception. Other guest-to-host escapes have also come through the ZDI program throughout the year. In fact, VMware released a patch for just such a bug less than a week prior to this year’s competition. In this blog post, we look into CVE-2020-3947, which was submitted to the ZDI program ( ZDI-20-298 ) in late December by an anonymous researcher. The vulnerability affects the DHCP server component of VMware Workstation a
Trendmicro
Vulnerability in the VMware Workstation
blogs_trendmicro·2020-04-02·CVSS 8.8
CVE-2020-3947 [HIGH] Vulnerability in the VMware Workstation
## CVE-2020-3947: Use-After-Free Vulnerability in the VMware Workstation DHCP Component
Learn about the vulnerability in the VMware workstation.
By: Zero Day Initiative 2020/04/02 Read time: ( words)
Save to Folio
Ever since introducing the virtualization category at Pwn2Own in 2016, guest-to-host escapes have been a highlight of the contest. This year’s event was no exception. Other guest-to-host escapes have also come through the ZDI program throughout the year. In fact, VMware released a patch for just such a bug less than a week prior to this year’s competition. In this blog post, we look into CVE-2020-3947, which was submitted to the ZDI program ( ZDI-20-298 ) in late December by an anonymous researcher. The vulnerability affects the DHCP server component of VMware Workstation and
2020-03-16
Published