Saturday, April 26, 2025
HomeCVE/vulnerabilityVMware Fixes High-severity Flaw that Affects VMware Workstation, Fusion and vSphere Products

VMware Fixes High-severity Flaw that Affects VMware Workstation, Fusion and vSphere Products

Published on

SIEM as a Service

Follow Us on Google News

VMware fixes a high-severity vulnerability that affects multiple products, exploitation allows attackers to obtain sensitive information.

VMware Vulnerabilities

CVE-2020-3960

The out-of-bounds read vulnerability affects VMware ESXi, Workstation, and Fusion, users are recommended to update with the fixed versions.

“A malicious actor with local non-administrative access to a virtual machine may be able to read privileged information contained in a memory,” reads advisory.

- Advertisement - Google News

CVE-2020-3961

A privilege escalation vulnerability that exists with VMware Horizon Client for Windows due to folder permission configuration and unsafe loading of libraries.

The vulnerability can be exploited by a local user on the system and them able to run commands as any user.

The vulnerability affects Horizon Client for Windows 5.x and prior, fixed with version 5.4.3, the vulnerability considered as important severity range and CVSSv3 base score of 8.4.

CVE-2020-3956

A code injection vulnerability with VMware Cloud Director leads to arbitrary remote code execution. The vulnerability can be exploited by threat actors by sending malicious traffic to VMware Cloud Director.

“This vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface, and API access,” reads the advisory.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

DragonForce and Anubis Ransomware Gangs Launch New Affiliate Programs

Secureworks Counter Threat Unit (CTU) researchers have uncovered innovative strategies deployed by the DragonForce...

“Power Parasites” Phishing Campaign Targets Energy Firms and Major Brands

Silent Push Threat Analysts have uncovered a widespread phishing and scam operation dubbed "Power...

Threat Actors Register Over 26,000 Domains Imitating Brands to Deceive Users

Researchers from Unit 42 have uncovered a massive wave of SMS phishing, or "smishing,"...

Russian Hackers Attempt to Sabotage Digital Control Systems of Dutch Public Service

The Dutch Defense Ministry has revealed that critical infrastructure, democratic processes, and North Sea...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Chrome UAF Process Vulnerabilities Actively Exploited

Security researchers have revealed that two critical use-after-free (UAF) vulnerabilities in Google Chrome’s Browser...

Spring Security Vulnerability Exposes Valid Usernames to Attackers

A newly identified security vulnerability, CVE-2025-22234, has exposed a critical weakness in the widely-used...

SAP NetWeaver 0-Day Vulnerability Enables Webshell Deployment

Cybersecurity analysts have issued a high-priority warning after several incidents revealed active exploitation of...