KLA12100
Multiple vulnerabilities in VMware Workstation and Player

Updated: 03/10/2021
Detect date
?
10/20/2020
Severity
?
Warning
Description

Multiple vulnerabilities were found in VMware Workstation and Player. Malicious users can exploit these vulnerabilities to obtain sensitive information, cause denial of service.

Below is a complete list of vulnerabilities:

  1. An out of bounds read vulnerability in ACPI device can be exploited to obtain sensitive information.
  2. An out of bounds write vulnerability in ACPI device can be exploited to cause denial of service.
  3. A memory leak vulnerability in VMCI host driver can be exploited to obtain sensitive information.
Affected products

VMware Workstation 15.x earlier than 15.5.7
VMware Player 15.x earlier than 15.5.7

Solution

Update to the latest version
Download VMWare Workstation

Original advisories

VMSA-2020-0023

Impacts
?
OSI 
[?]

DoS 
[?]
Related products
VMware Workstation
VMware Player
CVE-IDS
?
CVE-2020-39813.5Warning
CVE-2020-39824.9Warning
CVE-2020-39953.5Warning
Find out the statistics of the vulnerabilities spreading in your region