CVE-2020-3948: High severity VMware Fusion vulnerability
Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privilege escalation vulnerability due to improper file permissions in Cortado Thinprint. Local attackers with non-administrative access to a Linux guest VM with virtual printing enabled may exploit this issue to elevate their privileges to root on the same guest VM.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable virtual printing (Cortado Thinprint) in the affected Linux guest VMs to prevent local non-admin attackers from exploiting the improper file permissions for privilege escalation.
Cortado Thinprint virtual printing = disabled
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-3948.
What is the severity of CVE-2020-3948?
The severity of CVE-2020-3948 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2020-3948?
VMware Workstation versions 15.0.0 to 15.5.2 and VMware Fusion versions 11.0.0 to 11.5.2 are affected by CVE-2020-3948.
What is the cause of CVE-2020-3948?
CVE-2020-3948 is caused by improper file permissions in Cortado Thinprint in Linux Guest VMs running on VMware Workstation and Fusion.
How can I mitigate CVE-2020-3948?
To mitigate CVE-2020-3948, it is recommended to update VMware Workstation to version 15.5.2 or later, and VMware Fusion to version 11.5.2 or later.