KLA12098
Multiple vulnerabilities in VMware Workstation and Player

Updated: 03/10/2021
Detect date
?
06/23/2020
Severity
?
Warning
Description

Multiple vulnerabilities were found in VMware Workstation and Player. Malicious users can exploit these vulnerabilities to obtain sensitive information, execute arbitrary code, cause denial of service.

Below is a complete list of vulnerabilities:

  1. A out-of-bound read vulnerability in Shader Functionality can be exploited locally to cause denial of service.
  2. A information leak vulnerability in the EHCI USB controller can be exploited locally to obtain sensitive information.
  3. A heap overflow vulnerability in EHCI controller can be exploited locally to execute arbitrary code.
  4. A use after free vulnerability in SVGA device can be exploited locally to execute arbitrary code.
  5. A information leak vulnerability in the XHCI USB controller can be exploited locally to obtain sensitive information.
  6. A out of bounds write vulnerability in xHCI controller can be exploited locally to cause denial of service or execute arbitrary code.
  7. A heap overflow vulnerability in vmxnet3 can be exploited locally to obtain sensitive information.
  8. A heap overflow vulnerability in SVGA device can be exploited locally to execute arbitrary code.
  9. A use after free vulnerability in PVNVRAM can be exploited to obtain sensitive infromation.
Affected products

VMware Workstation 15.x earlier than 15.5.5
VMware Player 15.x earlier than 15.5.5

Solution

Update to the latest version
Download VMWare Workstation

Original advisories

VMSA-2020-0015

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]
Related products
VMware Workstation
VMware Player
CVE-IDS
?
CVE-2020-39700.0Unknown
CVE-2020-39640.0Unknown
CVE-2020-39660.0Unknown
CVE-2020-39620.0Unknown
CVE-2020-39650.0Unknown
CVE-2020-39680.0Unknown
CVE-2020-39710.0Unknown
CVE-2020-39670.0Unknown
CVE-2020-39690.0Unknown
CVE-2020-39630.0Unknown
Find out the statistics of the vulnerabilities spreading in your region