
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-3965 is an information leak vulnerability discovered in the XHCI USB controller affecting VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG, and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2). The vulnerability was reported by Cfir Cohen of Google Cloud security team and was publicly disclosed on June 23, 2020. VMware has evaluated this vulnerability with a CVSSv3 base score of 7.1, categorizing it as an Important severity issue (VMware Advisory).
The vulnerability stems from insufficient validation in the XHCI USB controller when reading DCBs (Device Context Buffers) from the guest. The issue occurs when mapping a guest page and iterating over values based on a bit field value. Specifically, a guest can supply a size value of 0x40 with a bit field value of 0xffffffff, causing the loop to copy 32 elements outside the bounds of the mapped region (Full Disclosure).
A malicious actor with local access to a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine. This information leak could potentially expose sensitive data and compromise the security of the hypervisor (VMware Advisory).
The vulnerability requires local access to a virtual machine to exploit. No additional conditions beyond the attacker's control need to be present for exploitation, making it relatively straightforward to exploit compared to other vulnerabilities disclosed in the same advisory (VMware Advisory).
VMware has released patches to address this vulnerability. Users should upgrade to the following versions: ESXi_7.0.0-1.20.16321839 for ESXi 7.0, ESXi670-202006401-SG for ESXi 6.7, ESXi650-202005401-SG for ESXi 6.5, version 11.5.2 for Fusion, and version 15.5.2 for Workstation. As a workaround, administrators can remove the USB Controller from affected virtual machines (VMware Advisory).
The vulnerability was part of a larger security update from VMware that addressed multiple vulnerabilities. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an alert warning that an attacker could exploit some of these vulnerabilities to take control of affected systems (Bleeping Computer).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."