CVE-2020-3950
VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac
Published 17 Mar 2020 · updated 17 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.
References
- packetstormsecurity.com/files/156843/VMware-Fusion-11.5.2-Privilege-Escalation.html · Exploit, Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/157079/VMware-Fusion-USB-Arbitrator-Setuid-Privilege-Escalation.html · Exploit, Third Party Advisory, VDB Entry
- www.vmware.com/security/advisories/VMSA-2020-0005.html · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3950 · US Government Resource