Permissions, Privileges, and Access Controls in VMware, Inc products - CVE-2020-3950
Published: March 17, 2020 / Updated: October 9, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper use of setuid binaries. A local user can execute arbitrary code on the system with elevated privileges.
Note: the vulnerability affects VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac.
Affected software
VMRC
VMware Fusion
How to mitigate CVE-2020-3950
VMRC - update to 11.0.1
VMware Fusion - update to 11.5.2