CVE-2020-3959: VMware ESXi

Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.

VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMware Fusion (11.x before 11.1.0) contain a memory leak vulnerability in the VMCI module. A malicious actor with local non-administrative access to a virtual machine may be able to crash the virtual machine's vmx process leading to a partial denial of service.

Affected products

  • VMware ESXi: version 6.5 only; version 6.7 only
  • VMware Fusion: from 11.0.0, before 11.1.0 (fixed in 11.1.0)
  • VMware Workstation: from 15.0.0, before 15.1.0 (fixed in 15.1.0)

Published 2020-05-29. Last modified 2026-06-17.