CVE-2020-3950 is a privilege escalation vulnerability affecting VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1), and Horizon Client for Mac (5.x and prior before 5.4.0) due to improper use of setuid binaries. This vulnerability has a CVSS score of 7.8 (High) and allows a local attacker with normal user privileges to escalate to root, with low attack complexity and no user interaction required. It is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0.0, < 11.5.2CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.4.0CPE matchmatch criteria | cpe:2.3:a:vmware:horizon_client:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.0.1CPE matchmatch criteria | cpe:2.3:a:vmware:remote_console:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.