CVE-2020-3950
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- VMware Multiple Products Privilege Escalation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 7% (אחוזון 100) נכון ל-4/8/2026
- CWE
- CWE-269
מוצרים מושפעים
vmware: fusion; vmware: horizon client; vmware: remote console; apple: macos
קישורים
- https://www.vmware.com/security/advisories/VMSA-2020-0005.html Vendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2020-0005.html Vendor Advisory
- http://packetstormsecurity.com/files/156843/VMware-Fusion-11.5.2-Privilege-Esc… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157079/VMware-Fusion-USB-Arbitrator-Setui… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/156843/VMware-Fusion-11.5.2-Privilege-Esc… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157079/VMware-Fusion-USB-Arbitrator-Setui… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource