7.2
CVSSv2

CVE-2020-3950

Published: 17/03/2020 Updated: 12/07/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

VMware Fusion (11.x prior to 11.5.2), VMware Remote Console for Mac (11.x and prior prior to 11.0.1) and Horizon Client for Mac (5.x and prior prior to 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware fusion

vmware horizon_client

vmware remote_console

Exploits

# Exploit Title: VMware Fusion 1152 - Privilege Escalation # Date: 2020-03-17 # Exploit Author: Rich Mirch # Vendor Homepage: wwwvmwarecom/products/fusionhtml # Vendor Advisory: wwwvmwarecom/security/advisories/VMSA-2020-0005html # Software Link: download3vmwarecom/software/fusion/file/VMware-Fusion-1151-15018442 ...
VMware Fusion version 1152 suffers from a privilege escalation vulnerability ...