CVE-2020-3982
published 2020-10-20CVE-2020-3982: VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before…
PriorityP339high7.7CVSS 3.1
AVNACHPRHUINSCCNIHAH
EPSS
0.83%
53.6th percentile
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a virtual machine may be able to exploit this vulnerability to crash the virtual machine's vmx process or corrupt hypervisor's memory heap.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 3.0 < 3.10.1 | 3.10.1 |
| vmware | cloud_foundation | >= 4.0 < 4.1 | 4.1 |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | >= 11.0 < 11.5.6 | 11.5.6 |
| vmware | workstation | 15.0 – 15.5.6 | — |
| vmware | workstation_player | 15.0 – 15.5.6 | — |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v5g8-mmh3-rp62: VMware ESXi (7
ghsa_unreviewed·2022-05-24
CVE-2020-3982 [HIGH] CWE-787 GHSA-v5g8-mmh3-rp62: VMware ESXi (7
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a virtual machine may be able to exploit this vulnerability to crash the virtual machine's vmx process or corrupt hypervisor's memory heap.
VMware
VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities (CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995)
vendor_vmware·2020-10-20·CVSS 5.8
CVE-2020-3981 [MEDIUM] VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities (CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995)
VMSA-2020-0023: VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities (CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995)
OpenSLP as used in ESXi has a use-after-free issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2020-3981, CVE-2020-3982, CVE-2020-3992, CVE-2020-3993, CVE-2020-3994, CVE-2020-3995
Affected products: Fusion Pro, NSX-T, VMware Cloud Foundation, VMware ESXi, VMware Fusion, VMware NSX, VMware Workstation, VMware vCenter Server, VMware vSphere, Workstation Player, Workstation Pro
No detection rules found.
No public exploits indexed.
Trendmicro
Detailing Two VMware Workstation TOCTOU Vulnerabilities
blogs_trendmicro·2020-10-22
Detailing Two VMware Workstation TOCTOU Vulnerabilities
## Detailing Two VMware Workstation TOCTOU Vulnerabilities
This post details two VMware workstation TOCTOU vulnerabilities.
By: Zero Day Initiative 2020/10/22 Read time: ( words)
Save to Folio
On October 20, VMware released a security patch addressing six vulnerabilities in VMware ESXi, Workstation, Fusion, and NSX-T. Two of those bugs fall into the category of Time-of-check Time-of-use (TOCTOU) race conditions. Now that the patch is out, I wanted to detail these TOCTOU bugs and their impact on VMware systems.
The Vulnerability
VMware Workstation uses a modified PhoenixBIOS 4.0 Release 6 for its legacy BIOS emulation. One of the modifications observed during the analysis of the BIOS.440.ROM image is the usage of a VMware backdoor. “Backdoor” in this context does not have any malign i
Trendmicro
Detailing Two VMware Workstation TOCTOU Vulnerabilities
blogs_trendmicro·2020-10-22
Detailing Two VMware Workstation TOCTOU Vulnerabilities
# Detailing Two VMware Workstation TOCTOU Vulnerabilities
This post details two VMware workstation TOCTOU vulnerabilities.
By: Zero Day Initiative
2020/10/22
Read time: ( words)
Save to Folio
On October 20, VMware released a security patch addressing six vulnerabilities in VMware ESXi, Workstation, Fusion, and NSX-T. Two of those bugs fall into the category of Time-of-check Time-of-use (TOCTOU) race conditions. Now that the patch is out, I wanted to detail these TOCTOU bugs and their impact on VMware systems.
The Vulnerability
VMware Workstation uses a modified PhoenixBIOS 4.0 Release 6 for its legacy BIOS emulation. One of the modifications observed during the analysis of the BIOS.440.ROM image is the usage of a VMware backdoor. “Backdoor” in this context does not have any malign i
Trendmicro
Detailing Two VMware Workstation TOCTOU Vulnerabilities
blogs_trendmicro·2020-10-22
Detailing Two VMware Workstation TOCTOU Vulnerabilities
## Detailing Two VMware Workstation TOCTOU Vulnerabilities
This post details two VMware workstation TOCTOU vulnerabilities.
By: Zero Day Initiative Oct 22, 2020 Read time: ( words)
Save to Folio
On October 20, VMware released a security patch addressing six vulnerabilities in VMware ESXi, Workstation, Fusion, and NSX-T. Two of those bugs fall into the category of Time-of-check Time-of-use (TOCTOU) race conditions. Now that the patch is out, I wanted to detail these TOCTOU bugs and their impact on VMware systems.
The Vulnerability
VMware Workstation uses a modified PhoenixBIOS 4.0 Release 6 for its legacy BIOS emulation. One of the modifications observed during the analysis of the BIOS.440.ROM image is the usage of a VMware backdoor. “Backdoor” in this context does not have any malign
2020-10-20
Published