CVE-2020-3948 is a local privilege escalation vulnerability affecting Linux guest virtual machines running on VMware Workstation (versions prior to 15.5.2) and Fusion (versions prior to 11.5.2). The flaw stems from improper file permissions within the Cortado Thinprint component. This vulnerability has a CVSS score of 7.8 (High), indicating that a local attacker with non-administrative access can exploit it to gain root privileges on the guest VM, leading to high impact on confidentiality, integrity, and availability. The attack complexity is low, as it does not require user interaction. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including an article from SecurityWeek. It is not listed on the CISA KEV catalog and is currently inactive on the Hot List, suggesting no widespread active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0.0, < 11.5.2CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* | ||
>= 15.0.0, < 15.5.2CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.