VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrative access to a virtual machine with a virtual NVMe controller present may be able to read privileged information contained in physical memory.
The product reads data past the end, or before the beginning, of the intended buffer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Fusion | Vmware | 11.0.0 (including) | 11.5.5 (excluding) |
| Workstation | Vmware | 15.0.0 (including) | 15.5.5 (excluding) |
| Vsphere_esxi | Vmware | 6.5 (including) | 6.5 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201701001 (including) | 6.5-650-201701001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201703001 (including) | 6.5-650-201703001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201703002 (including) | 6.5-650-201703002 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201704001 (including) | 6.5-650-201704001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201710001 (including) | 6.5-650-201710001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201712001 (including) | 6.5-650-201712001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201803001 (including) | 6.5-650-201803001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201806001 (including) | 6.5-650-201806001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201808001 (including) | 6.5-650-201808001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201810001 (including) | 6.5-650-201810001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201810002 (including) | 6.5-650-201810002 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201811001 (including) | 6.5-650-201811001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201901001 (including) | 6.5-650-201901001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201903001 (including) | 6.5-650-201903001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201905001 (including) | 6.5-650-201905001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201908001 (including) | 6.5-650-201908001 (including) |
| Vsphere_esxi | Vmware | 6.5-650-201910001 (including) | 6.5-650-201910001 (including) |
| Vsphere_esxi | Vmware | 6.7 (including) | 6.7 (including) |
| Vsphere_esxi | Vmware | 6.7-670-201911001 (including) | 6.7-670-201911001 (including) |
| Vsphere_esxi | Vmware | 6.7-670-202004001 (including) | 6.7-670-202004001 (including) |