CVE-2020-3969 is an off-by-one heap-overflow vulnerability in the SVGA device of VMware ESXi, Workstation, and Fusion. A malicious actor with local access to a virtual machine with 3D graphics enabled could potentially exploit this to execute code on the hypervisor. This vulnerability has a CVSS score of 7.8 (HIGH), indicating a significant impact with high confidentiality, integrity, and availability concerns, though exploitation requires additional conditions beyond the attacker's control and has high attack complexity. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting it is not widely targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, < 3.10CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.1CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.5.5CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* | ||
>= 15.0.0, < 15.5.5CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.5:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.