CVE-2020-3964

MEDIUM

VMware ESXi 6.5-7.0, Workstation 15.x, Fusion 11.x - Information Leak in EHCI USB Controller

Title source: llm
STIX 2.1

Description

VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the EHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained in the hypervisor's memory. Additional conditions beyond the attacker's control need to be present for exploitation to be possible.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Jul/22

Scores

CVSS v3 4.7
EPSS 0.0011
EPSS Percentile 29.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-908
Status published
Products (2)
vmware/cloud_foundation 3.0 - 3.10
vmware/esxi 6.5 (49 CPE variants)
Published Jun 25, 2020
Tracked Since Feb 18, 2026