Main
Vulnerability Database
Exploits
ID:5739 - Exploit for Permissions, Privileges, and Access Controls in VMware, Inc products - CVE-2020-3950
ID:5739 - Exploit for Permissions, Privileges, and Access Controls in VMware, Inc products - CVE-2020-3950
Published: June 17, 2021
Vulnerability identifier: #VU26147
Vulnerability risk: Low
CVE-ID: CVE-2020-3950
CWE-ID: CWE-264
Exploitation vector: Local access
Vulnerable software:
VMware Fusion
VMRC
VMware Horizon Client
VMware Fusion
VMRC
VMware Horizon Client
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper use of setuid binaries. A local user can execute arbitrary code on the system with elevated privileges.
Note: the vulnerability affects VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac.
Remediation
Install updates from vendor's website.