Vmware Workstation vulnerabilities

225 known vulnerabilities affecting vmware/workstation.

Total CVEs
225
CISA KEV
2
actively exploited
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL32HIGH90MEDIUM88LOW15

Vulnerabilities

Page 3 of 12
CVE-2020-3968HIGHCVSS 8.2≥ 15.0.0, < 15.5.5v15.x before 15.5.52020-06-25
CVE-2020-3968 [HIGH] CWE-787 CVE-2020-3968: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xHCI). A malicious actor with local administrative privileges on a virtual machine may be able to
cvelistv5nvd
CVE-2020-3966HIGHCVSS 7.5≥ 15.0.0, < 15.5.2v15.x before 15.5.22020-06-25
CVE-2020-3966 [HIGH] CWE-362 CVE-2020-3966: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit t
cvelistv5nvd
CVE-2020-3964MEDIUMCVSS 4.7≥ 15.0.0, < 15.5.2v15.x before 15.5.22020-06-25
CVE-2020-3964 [MEDIUM] CWE-908 CVE-2020-3964: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the EHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained i
cvelistv5nvd
CVE-2020-3965MEDIUMCVSS 5.5≥ 15.0.0, < 15.5.2v15.x before 15.5.22020-06-25
CVE-2020-3965 [MEDIUM] CWE-125 CVE-2020-3965: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the XHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained i
cvelistv5nvd
CVE-2020-3971MEDIUMCVSS 5.5≥ 15.0.0, < 15.0.2v15.x before 15.0.22020-06-25
CVE-2020-3971 [MEDIUM] CWE-787 CVE-2020-3971: VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201907101-SG), Workstation (15.x before 15.0.2), and Fusion (11.x before 11.0.2) contain a heap overflow vulnerability in the vmxnet3 virtual network adapter. A malicious actor with local access to a virtual machine with a vmxnet3 network adapter present may be able to read privileged
cvelistv5nvd
CVE-2020-3963MEDIUMCVSS 5.5≥ 15.0.0, < 15.5.2v15.x before 15.5.22020-06-25
CVE-2020-3963 [MEDIUM] CWE-416 CVE-2020-3963: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with local access to a virtual machine may be able to read privileged information contained in phy
cvelistv5nvd
CVE-2020-3970LOWCVSS 3.8≥ 15.0.0, < 15.5.5v15.x before 15.5.52020-06-25
CVE-2020-3970 [LOW] CWE-125 CVE-2020-3970: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in the Shader functionality. A malicious actor with non-administrative local access to a virtual machine with 3D graphics enab
cvelistv5nvd
CVE-2020-3969HIGHCVSS 7.8≥ 15.0.0, < 15.5.5v15.x before 15.5.52020-06-24
CVE-2020-3969 [HIGH] CWE-193 CVE-2020-3969: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an off-by-one heap-overflow vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with 3D graphics enabled may be able to ex
cvelistv5nvd
CVE-2020-3962HIGHCVSS 8.2≥ 15.0.0, < 15.5.5v15.x before 15.5.52020-06-24
CVE-2020-3962 [HIGH] CWE-416 CVE-2020-3962: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a use-after-free vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with 3D graphics enabled may be able to exploit this
cvelistv5nvd
CVE-2020-3958MEDIUMCVSS 5.5≥ 15.0.0, < 15.5.22020-05-29
CVE-2020-3958 [MEDIUM] CWE-617 CVE-2020-3958: VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstatio VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x before 11.5.2) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with non-administrative access to a virtual machine to crash t
nvd
CVE-2020-3959LOWCVSS 3.3≥ 15.0.0, < 15.1.02020-05-29
CVE-2020-3959 [LOW] CWE-401 CVE-2020-3959: VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstatio VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMware Fusion (11.x before 11.1.0) contain a memory leak vulnerability in the VMCI module. A malicious actor with local non-administrative access to a virtual machine may be able to crash the virtual machine's vmx process leading
nvd
CVE-2020-3951LOWCVSS 3.8≥ 15.0.0, < 15.5.22020-03-17
CVE-2020-3951 [LOW] CWE-787 CVE-2020-3951: VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-service vulnerability due to a heap-overflow issue in Cortado Thinprint. Attackers with non-administrative access to a guest VM with virtual printing enabled may exploit this issue to create a denial-of-service condition of the Thinprint
nvd
CVE-2019-5543HIGHCVSS 7.8≥ 15.0.0, < 15.5.22020-03-16
CVE-2019-5543 [HIGH] CWE-732 CVE-2019-5543: For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Window For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Windows (15.x before 15.5.2) the folder containing configuration files for the VMware USB arbitration service was found to be writable by all users. A local user on the system where the software is installed
nvd
CVE-2020-3948HIGHCVSS 7.8≥ 15.0.0, < 15.5.2v15.x before 15.5.22020-03-16
CVE-2020-3948 [HIGH] CWE-732 CVE-2020-3948: Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) c Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privilege escalation vulnerability due to improper file permissions in Cortado Thinprint. Local attackers with non-administrative access to a Linux guest VM with virtual printing enabled may exploit this issue to elevate their privileges to
cvelistv5nvd
CVE-2020-3947HIGHCVSS 8.8≥ 15.0.0, < 15.5.2v15.x before 15.5.22020-03-16
CVE-2020-3947 [HIGH] CWE-416 CVE-2020-3947: VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerab VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition of the vmnetdhcp service running on the host machine.
cvelistv5nvd
CVE-2019-5539HIGHCVSS 7.8≥ 15.0.0, < 15.5.12019-12-23
CVE-2019-5539 [HIGH] CWE-427 CVE-2019-5539: VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x p VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows ma
nvd
CVE-2019-5098HIGHCVSS 8.6v15.0.02019-12-05
CVE-2019-5098 [HIGH] CWE-125 CVE-2019-5098: An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.130 An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can cause out-of-bounds memory read. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.
nvd
CVE-2019-5541CRITICALCVSS 9.1≥ 15.0.0, < 15.5.12019-11-20
CVE-2019-5541 [CRITICAL] CWE-787 CVE-2019-5541: VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds wri VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition on their own VM.
nvd
CVE-2019-5540HIGHCVSS 7.7≥ 15.0.0, < 15.5.12019-11-20
CVE-2019-5540 [HIGH] CWE-401 CVE-2019-5540: VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information discl VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory from the host process.
nvd
CVE-2019-5542HIGHCVSS 7.7≥ 15.0.0, < 15.5.12019-11-20
CVE-2019-5542 [HIGH] CVE-2019-5542: VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM.
nvd