First published: Fri May 29 2020(Updated: )
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC and Horizon Client are installed.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Fusion | >=11.0.0<11.5.5 | |
Vmware Horizon Client | <=5.4.0 | |
VMware Remote Console | <=11.0.1 | |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-3957.
The severity of CVE-2020-3957 is high (7 out of 10).
VMware Fusion versions 11.x before 11.5.5, VMware Remote Console for Mac versions 11.x and prior, and VMware Horizon Client for Mac versions 5.x and prior are affected by CVE-2020-3957.
This vulnerability can be exploited through a Time-of-check Time-of-use (TOCTOU) issue in the service opener.
No, Apple macOS is not affected by CVE-2020-3957.