← Back

CVE-2020-4004

nvd nist
Published: Nov 20, 2020Modified: Oct 31, 2025

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.5 / Impact: 6.0
Source: NVD

Description

VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

Affected (183)

4 products
Fusion
Cloud Foundation
Workstation
Esxi
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 11.0 to 11.5.7
Running on/withPlatform Versions
Apple
Mac Os X
All versions
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
From 3.0 to 3.10.1.2
From 4.0 to 4.1.0.1
From 15.0.0 to 15.5.7
Configuration C
65 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Version 6.5
Version 6.5 650-201701001
Version 6.5 650-201703001
Version 6.5 650-201703002
Version 6.5 650-201704001
Version 6.5 650-201707101
Version 6.5 650-201707102
Version 6.5 650-201707103
Version 6.5 650-201707201
Version 6.5 650-201707202
Version 6.5 650-201707203
Version 6.5 650-201707204
Version 6.5 650-201707205
Version 6.5 650-201707206
Version 6.5 650-201707207
Version 6.5 650-201707208
Version 6.5 650-201707209
Version 6.5 650-201707210
Version 6.5 650-201707211
Version 6.5 650-201707212
Version 6.5 650-201707213
Version 6.5 650-201707214
Version 6.5 650-201707215
Version 6.5 650-201707216
Version 6.5 650-201707217
Version 6.5 650-201707218
Version 6.5 650-201707219
Version 6.5 650-201707220
Version 6.5 650-201707221
Version 6.5 650-201710001
Version 6.5 650-201712001
Version 6.5 650-201803001
Version 6.5 650-201806001
Version 6.5 650-201808001
Version 6.5 650-201810001
Version 6.5 650-201810002
Version 6.5 650-201811001
Version 6.5 650-201811002
Version 6.5 650-201811301
Version 6.5 650-201901001
Version 6.5 650-201903001
Version 6.5 650-201905001
Version 6.5 650-201908001
Version 6.5 650-201910001
Version 6.5 650-20191004001
Version 6.5 650-201911001
Version 6.5 650-201911401
Version 6.5 650-201911402
Version 6.5 650-201912001
Version 6.5 650-201912002
Version 6.5 650-201912101
Version 6.5 650-201912102
Version 6.5 650-201912103
Version 6.5 650-201912104
Version 6.5 650-201912301
Version 6.5 650-201912401
Version 6.5 650-201912402
Version 6.5 650-201912403
Version 6.5 650-201912404
Version 6.5 650-202005001
Version 6.5 650-202006001
Version 6.5 650-202007001
Version 6.5 650-202010001
Version 6.5 650-202011001
Version 6.5 650-202011002
Configuration D
109 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Version 6.7
Version 6.7 670-201806001
Version 6.7 670-201807001
Version 6.7 670-201808001
Version 6.7 670-201810001
Version 6.7 670-201810101
Version 6.7 670-201810102
Version 6.7 670-201810103
Version 6.7 670-201810201
Version 6.7 670-201810202
Version 6.7 670-201810203
Version 6.7 670-201810204
Version 6.7 670-201810205
Version 6.7 670-201810206
Version 6.7 670-201810207
Version 6.7 670-201810208
Version 6.7 670-201810209
Version 6.7 670-201810210
Version 6.7 670-201810211
Version 6.7 670-201810212
Version 6.7 670-201810213
Version 6.7 670-201810214
Version 6.7 670-201810215
Version 6.7 670-201810216
Version 6.7 670-201810217
Version 6.7 670-201810218
Version 6.7 670-201810219
Version 6.7 670-201810220
Version 6.7 670-201810221
Version 6.7 670-201810222
Version 6.7 670-201810223
Version 6.7 670-201810224
Version 6.7 670-201810225
Version 6.7 670-201810226
Version 6.7 670-201810227
Version 6.7 670-201810228
Version 6.7 670-201810229
Version 6.7 670-201810230
Version 6.7 670-201810231
Version 6.7 670-201810232
Version 6.7 670-201810233
Version 6.7 670-201810234
Version 6.7 670-201811001
Version 6.7 670-201901001
Version 6.7 670-201901401
Version 6.7 670-201901402
Version 6.7 670-201901403
Version 6.7 670-201903001
Version 6.7 670-201904001
Version 6.7 670-201904201-ug
Version 6.7 670-201904201
Version 6.7 670-201904202-ug
Version 6.7 670-201904202
Version 6.7 670-201904203-ug
Version 6.7 670-201904203
Version 6.7 670-201904204-ug
Version 6.7 670-201904204
Version 6.7 670-201904205-ug
Version 6.7 670-201904205
Version 6.7 670-201904206-ug
Version 6.7 670-201904206
Version 6.7 670-201904207-ug
Version 6.7 670-201904207
Version 6.7 670-201904208-ug
Version 6.7 670-201904208
Version 6.7 670-201904209-ug
Version 6.7 670-201904209
Version 6.7 670-201904210-ug
Version 6.7 670-201904210
Version 6.7 670-201904211-ug
Version 6.7 670-201904211
Version 6.7 670-201904212-ug
Version 6.7 670-201904212
Version 6.7 670-201904213-ug
Version 6.7 670-201904213
Version 6.7 670-201904214-ug
Version 6.7 670-201904214
Version 6.7 670-201904215-ug
Version 6.7 670-201904215
Version 6.7 670-201904216-ug
Version 6.7 670-201904216
Version 6.7 670-201904217-ug
Version 6.7 670-201904217
Version 6.7 670-201904218-ug
Version 6.7 670-201904218
Version 6.7 670-201904219-ug
Version 6.7 670-201904219
Version 6.7 670-201904220-ug
Version 6.7 670-201904220
Version 6.7 670-201904221-ug
Version 6.7 670-201904221
Version 6.7 670-201904222-ug
Version 6.7 670-201904222
Version 6.7 670-201904223-ug
Version 6.7 670-201904223
Version 6.7 670-201904224-ug
Version 6.7 670-201904224
Version 6.7 670-201904225-ug
Version 6.7 670-201904225
Version 6.7 670-201904226
Version 6.7 670-201905001
Version 6.7 670-201906002
Version 6.7 670-201911001
Version 6.7 670-201912001
Version 6.7 670-202004001
Version 6.7 670-202004002
Version 6.7 670-202006001
Version 6.7 670-202008001
Version 6.7 670-202010001
Configuration E
5 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Version 7.0
Version 7.0 beta
Version 7.0 update_1
Version 7.0 update_1a
Version 7.0 update_1b

References (2)

Source: security@vmware.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.