KLA12098
Multiple vulnerabilities in VMware Workstation and Player

Обновлено: 10/03/2021
Дата обнаружения
23/06/2020
Уровень угрозы
Warning
Описание

Multiple vulnerabilities were found in VMware Workstation and Player. Malicious users can exploit these vulnerabilities to obtain sensitive information, execute arbitrary code, cause denial of service.

Below is a complete list of vulnerabilities:

  1. A out-of-bound read vulnerability in Shader Functionality can be exploited locally to cause denial of service.
  2. A information leak vulnerability in the EHCI USB controller can be exploited locally to obtain sensitive information.
  3. A heap overflow vulnerability in EHCI controller can be exploited locally to execute arbitrary code.
  4. A use after free vulnerability in SVGA device can be exploited locally to execute arbitrary code.
  5. A information leak vulnerability in the XHCI USB controller can be exploited locally to obtain sensitive information.
  6. A out of bounds write vulnerability in xHCI controller can be exploited locally to cause denial of service or execute arbitrary code.
  7. A heap overflow vulnerability in vmxnet3 can be exploited locally to obtain sensitive information.
  8. A heap overflow vulnerability in SVGA device can be exploited locally to execute arbitrary code.
  9. A use after free vulnerability in PVNVRAM can be exploited to obtain sensitive infromation.
Пораженные продукты

VMware Workstation 15.x earlier than 15.5.5
VMware Player 15.x earlier than 15.5.5

Решение

Update to the latest version
Download VMWare Workstation

Первичный источник обнаружения
VMSA-2020-0015
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]
Связанные продукты
VMware Workstation
VMware Player
CVE-IDS
CVE-2020-39701.9Warning
CVE-2020-39641.9Warning
CVE-2020-39663.7Warning
CVE-2020-39624.4Warning
CVE-2020-39652.1Warning
CVE-2020-39684.6Warning
CVE-2020-39712.1Warning
CVE-2020-39674.4Warning
CVE-2020-39694.4Warning
CVE-2020-39632.1Warning
Узнай статистику распространения уязвимостей в твоем регионе