CVE-2020-3950highunder attackCWE-269

CVE-2020-3950: high-severity vulnerability in VMware Fusion, VMware Remote Console for Mac…

Published · Updated

86Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.8epss 7.3%
from disclosure to weapon0 days
Published on NVDMar 17
1st PoCNov 6
metasploitMar 17
CISA KEV+596d
exploitation probability
7.3%top 6% of all CVEs
observed exploitation
yesCISA + VulnCheck
5 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

VMware Fusion, Remote Console, and Horizon Client on Mac have a vulnerability that lets regular users gain root (administrator) access through improperly configured system programs. An attacker with a normal user account can exploit this to take full control of the computer.

Technical detail

The vulnerability exists in improper setuid binary configuration in VMware Fusion (11.x < 11.5.2), VMware Remote Console for Mac (≤11.0.0), and Horizon Client for Mac (≤5.3.x). A local attacker with standard user privileges can escalate to root by exploiting this misconfiguration, requiring only local access to the affected system. The attack vector is local with low attack complexity and no user interaction needed.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.