Vulnerability Name:

CVE-2020-3981 (CCN-190039)

Assigned:2019-12-30
Published:2020-10-20
Updated:2021-07-21
Summary:VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
CVSS v3 Severity:5.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N)
5.1 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
7.1 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)
6.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-367
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2020-3981

Source: XF
Type: UNKNOWN
vmware-cve20203981-info-disc(190039)

Source: CCN
Type: IBM Security Bulletin 6452221 (Cloud Pak System)
Multiple vulnerabilities in VMware affect IBM Cloud Pak System

Source: CCN
Type: VMware Security Advisory VMSA-2020-0023
VMware ESXi, Workstation, Fusion and NSX-T updates address multiple security vulnerabilities

Source: MISC
Type: Patch, Vendor Advisory
https://www.vmware.com/security/advisories/VMSA-2020-0023.html

Source: CCN
Type: ZDI-20-1267
VMware Workstation BDOOR_CMD_PATCH_ACPI_TABLES Time-Of-Check Time-Of-Use Information Disclosure Vulnerability

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/o:vmware:esxi:6.5:*:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:6.7:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:workstation:15.0:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:11.0:*:*:*:*:*:*:*
  • OR cpe:/o:vmware:esxi:7.0:-:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:cloud_pak_system:2.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    vmware esxi 6.5
    vmware esxi 6.7
    vmware workstation 15.0
    vmware fusion 11.0
    vmware esxi 7.0 -
    ibm cloud pak system 2.3