CVE-2020-3950
Summary
| CVE | CVE-2020-3950 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-17 19:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed. |
Risk And Classification
EPSS: 0.213690000 probability, percentile 0.956650000 (date 2026-04-01)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Unknown
Problem Types: CWE-269
CISA Known Exploited Vulnerability
| Vendor | VMware |
|---|---|
| Product | Multiple Products |
| Name | VMware Multiple Products Privilege Escalation Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2020-3950 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Macos | - | All | All | All |
| Operating System | Apple | Mac Os | - | All | All | All |
| Operating System | Apple | Mac Os | - | All | All | All |
| Application | Vmware | Fusion | All | All | All | All |
| Application | Vmware | Fusion | All | All | All | All |
| Application | Vmware | Horizon Client | All | All | All | All |
| Application | Vmware | Horizon Client | All | All | All | All |
| Application | Vmware | Remote Console | All | All | All | All |
| Application | Vmware | Remote Console | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware Fusion USB Arbitrator Setuid Privilege Escalation ≈ Packet Storm | MISC | packetstormsecurity.com | |
| VMware Fusion 11.5.2 Privilege Escalation ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory |
| VMSA-2020-0005 | MISC | www.vmware.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.