First published: Fri Jul 10 2020(Updated: )
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMware Remote Console for Mac or Horizon Client for Mac is installed.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Fusion | >=11.0.0<11.5.5 | |
Vmware Horizon Client | >=5.0.0<5.4.3 | |
VMware Remote Console | >=11.0.0<11.2.0 | |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3974 is a privilege escalation vulnerability in VMware Fusion, VMware Remote Console for Mac, and Horizon Client for Mac.
The severity of CVE-2020-3974 is high, with a severity score of 7.8 out of 10.
VMware Fusion versions before 11.5.5, VMware Remote Console for Mac versions before 11.2.0, and Horizon Client for Mac versions before 5.4.3 are affected.
CVE-2020-3974 is a privilege escalation vulnerability due to improper XPC Client validation.
You can find more information about CVE-2020-3974 in the advisory provided by VMware: [https://www.vmware.com/security/advisories/VMSA-2020-0017.html](https://www.vmware.com/security/advisories/VMSA-2020-0017.html).