CVE-2020-3974
Published on: 07/10/2020 12:00:00 AM UTC
Last Modified on: 09/08/2021 05:22:00 PM UTC
Certain versions of Macos from Apple contain the following vulnerability:
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMware Remote Console for Mac or Horizon Client for Mac is installed.
- CVE-2020-3974 has been assigned by
secu[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 7.2 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
VMSA-2020-0017 | Patch Vendor Advisory www.vmware.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Apple | Macos | - | All | All | All |
Operating System | Apple | Mac Os | - | All | All | All |
Operating System | Apple | Mac Os | - | All | All | All |
Application | Vmware | Fusion | All | All | All | All |
Application | Vmware | Fusion | All | All | All | All |
Application | Vmware | Horizon Client | All | All | All | All |
Application | Vmware | Horizon Client | All | All | All | All |
Application | Vmware | Remote Console | All | All | All | All |
Application | Vmware | Remote Console | All | All | All | All |
- cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os:-:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:mac_os:-:*:*:*:*:*:*:*:
- cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*:
- cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*:
- cpe:2.3:a:vmware:horizon_client:*:*:*:*:*:*:*:*:
- cpe:2.3:a:vmware:horizon_client:*:*:*:*:*:*:*:*:
- cpe:2.3:a:vmware:remote_console:*:*:*:*:*:*:*:*:
- cpe:2.3:a:vmware:remote_console:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE