
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-3958 is a denial-of-service vulnerability discovered in VMware ESXi (versions 6.7 and 6.5), VMware Workstation (15.x before 15.5.2), and VMware Fusion (11.x before 11.5.2). The vulnerability was identified in the shader functionality of these products and was publicly disclosed on May 17, 2020. VMware has evaluated this vulnerability to be of Moderate severity with a CVSSv3 base score of 4.0 (VMware Advisory).
The vulnerability exists in the shader functionality of affected VMware products. When exploited, a specially crafted pixel shader can trigger a panic condition in the vmware-vmx.exe process on the host system. The vulnerability requires an attacker to have access to a virtual machine with 3D graphics enabled, which is enabled by default on Workstation and Fusion but not on ESXi. The issue was discovered by Piotr Bania of Cisco Talos (VMware Advisory, Talos Report).
Successful exploitation of this vulnerability allows attackers with non-administrative access to a virtual machine to crash the virtual machine's vmx process, resulting in a denial of service condition. This impact is particularly significant for environments where virtual machine stability is crucial (VMware Advisory).
The vulnerability can be triggered from within a VMware guest operating system by supplying a malformed pixel shader. The attack can be executed from VMware guest usermode, or theoretically through WEBGL (remote website). The exploitation requires the attacker to have access to a virtual machine with 3D graphics enabled (Talos Report).
VMware has released patches to address this vulnerability. For VMware ESXi 6.7, users should update to ESXi670-202004101-SG, for ESXi 6.5 to ESXi650-202005401-SG, for Workstation 15.x to version 15.5.2, and for Fusion 11.x to version 11.5.2. Additional workaround information is available in KB59146 for Workstation and Fusion users (VMware Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."