Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

VMware Patches Several Vulnerabilities Allowing Code Execution on Hypervisor

VMware informed customers on Tuesday that it addressed a total of 10 vulnerabilities affecting its ESXi, Workstation and Fusion products, including critical and high-severity flaws that can be exploited for code execution on the hypervisor.

VMware informed customers on Tuesday that it addressed a total of 10 vulnerabilities affecting its ESXi, Workstation and Fusion products, including critical and high-severity flaws that can be exploited for code execution on the hypervisor.

The most serious of the vulnerabilities is CVE-2020-3962, a critical use-after-free bug related to the SVGA device. An attacker who has local access to a virtual machine (VM) with 3D graphics enabled can exploit the weakness for arbitrary code execution on the hypervisor from the VM.

VMware has pointed out that 3D graphics are enabled by default on Workstation and Fusion, but not on ESXi.

A very similar vulnerability patched this week by the virtualization giant is an off-by-one heap overflow bug related to the SVGA device. Exploitation of this vulnerability requires the same types of permissions and it can also result in code execution, but it has been rated high severity instead of critical due to the attack complexity being assigned as high — the attack complexity is considered low for the previous flaw.

“Additional conditions beyond the attacker’s control must be present for exploitation to be possible,” VMware said in its advisory.

Another high-severity vulnerability affecting ESXi, Workstation and Fusion has been described as a heap overflow affecting the USB 2.0 controller. Similar to the aforementioned security holes, this one also allows an attacker with local access to a VM to execute arbitrary code on the hypervisor.

Advertisement. Scroll to continue reading.

The same USB 2.0 controller is impacted by a race condition that causes a heap overflow. This bug can also allow arbitrary code execution on the hypervisor, but exploitation is only possible against certain configurations.

A high-severity vulnerability identified in the USB 3.0 controller allows an attacker with admin privileges on the VM to cause a denial-of-service (DoS) condition or execute arbitrary code on the hypervisor. Another high-severity issue affecting this controller can be leveraged by a local attacker to read privileged information from memory.

Other flaws patched by the company have been rated medium severity and they can be exploited by local attackers to cause a DoS condition or to read privileged information from memory.

Many of the vulnerabilities were reported to VMware by various researchers through Trend Micro’s Zero Day Initiative, and several were identified by a researcher from Google. The same Google employee was credited recently by VMware for a high-severity information disclosure flaw affecting Workstation, Fusion and vSphere.

Related: Details Released for Flaw Allowing Full Control Over VMware Deployments

Related: Hackers Can Compromise VMware vCenter Server Via Newly Patched Flaw

Related: Remote Code Execution Vulnerability Patched in VMware Cloud Director

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Devi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.

Forcepoint has named Proofpoint veteran Vincent Merlin as its new Chief Marketing Officer.

Vensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.