ID:5739 - Exploit for Permissions, Privileges, and Access Controls in VMware, Inc products - CVE-2020-3950

 
Main Vulnerability Database Exploits ID:5739 - Exploit for Permissions, Privileges, and Access Controls in VMware, Inc products - CVE-2020-3950

ID:5739 - Exploit for Permissions, Privileges, and Access Controls in VMware, Inc products - CVE-2020-3950

Published: June 17, 2021


Vulnerability identifier: #VU26147
Vulnerability risk: Low
CVE-ID: CVE-2020-3950
CWE-ID: CWE-264
Exploitation vector: Local access
Vulnerable software:
VMware Fusion
VMRC
VMware Horizon Client

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper use of setuid binaries. A local user can execute arbitrary code on the system with elevated privileges.

Note: the vulnerability affects VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac.


Remediation

Install updates from vendor's website.