ID:5197 - Exploit for Permissions, Privileges, and Access Controls in VMware Fusion - CVE-2020-3980

 
Main Vulnerability Database Exploits ID:5197 - Exploit for Permissions, Privileges, and Access Controls in VMware Fusion - CVE-2020-3980

ID:5197 - Exploit for Permissions, Privileges, and Access Controls in VMware Fusion - CVE-2020-3980

Published: March 7, 2021


Vulnerability identifier: #VU46759
Vulnerability risk: Low
CVE-ID: CVE-2020-3980
CWE-ID: CWE-264
Exploitation vector: Local access
Vulnerable software:
VMware Fusion

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to the way the affected software allows configuring the system wide path. A local user can trick an admin user into executing malicious code on the system where Fusion is installed.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.