Time-of-check Time-of-use (TOCTOU) Race Condition in VMware, Inc products - CVE-2020-3957
Published: May 29, 2020 / Updated: March 7, 2021
Vulnerability identifier: #VU28338
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3957
CWE-ID:
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. An local user can gain elevated privileges on the target system.
Affected software
VMware Horizon Client
VMRC
VMware Fusion
VMRC
VMware Fusion
How to mitigate CVE-2020-3957
Install updates from vendor's website.
VMware Fusion - update to 11.5.5