CVE-2020-3950
high · 7.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2021-11-03Remediation due 2022-05-03
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.
7.8
CVSS
7.3%
EPSS (exploit prob.)
94th
EPSS percentile
2020-03-17
Published
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-269
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| vmware | fusion | >= 11.0.0, < 11.5.2 |
| vmware | horizon_client | >= 5.0.0, < 5.4.0 |
| vmware | remote_console | >= 11.0.0, < 11.0.1 |
| apple | macos | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/156843/VMware-Fusion-11.5.2-Privilege-Escalation.html
- http://packetstormsecurity.com/files/157079/VMware-Fusion-USB-Arbitrator-Setuid-Privilege-Escalation.html
- https://www.vmware.com/security/advisories/VMSA-2020-0005.html
- http://packetstormsecurity.com/files/156843/VMware-Fusion-11.5.2-Privilege-Escalation.html
- http://packetstormsecurity.com/files/157079/VMware-Fusion-USB-Arbitrator-Setuid-Privilege-Escalation.html
- https://www.vmware.com/security/advisories/VMSA-2020-0005.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3950
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-3950