CVE-2020-3941 describes a race condition in the repair operation of VMware Tools for Windows versions 10.x.y, which could lead to privilege escalation within the virtual machine. This vulnerability is not present in VMware Tools 11.x.y. With a CVSS score of 7.0 (HIGH), it requires local access and high attack complexity, but successful exploitation could grant high confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 11.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.