CVE-2020-3957: High severity vmware fusion vulnerability
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC and Horizon Client are installed.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-3957.
What is the severity of CVE-2020-3957?
The severity of CVE-2020-3957 is high (7 out of 10).
Which software versions are affected by CVE-2020-3957?
VMware Fusion versions 11.x before 11.5.5, VMware Remote Console for Mac versions 11.x and prior, and VMware Horizon Client for Mac versions 5.x and prior are affected by CVE-2020-3957.
How can this vulnerability be exploited?
This vulnerability can be exploited through a Time-of-check Time-of-use (TOCTOU) issue in the service opener.
Is Apple macOS affected by CVE-2020-3957?
No, Apple macOS is not affected by CVE-2020-3957.