ZeroHour

CVE-2020-3950

KEV PoC ×2large

Setuid-Based Local Privilege Escalation in VMware Fusion and Mac Clients

CISA: VMware Multiple Products Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
7%p94
Published
()
KEV added
AI analysis

VMware Fusion, VMware Remote Console for Mac, and Horizon Client for Mac contain a local privilege escalation flaw (CWE-269, Improper Privilege Management) caused by improper use of setuid binaries, which run with elevated privileges when executed. An attacker who already has normal (non-root) user access to a Mac where one of these products is installed can invoke the misconfigured setuid binaries to execute code as root. Successful exploitation grants full root-level control over the affected machine, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Only macOS installations of Fusion 11.x before 11.5.2, VMRC for Mac 11.x and prior before 11.0.1, and Horizon Client for Mac 5.x and prior before 5.4.0 are affected. Public proof-of-concept exploits are available, and CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild; whether ransomware operators use it is unknown.

What to do: Upgrade affected Macs to VMware Fusion 11.5.2 or later, VMRC for Mac 11.0.1 or later, and Horizon Client for Mac 5.4.0 or later, per VMware's instructions. Because exploitation requires local user access, prioritize multi-user Macs and machines where untrusted users can execute code; inventory managed Macs for these products and verify installed versions. As the CVE is on the CISA KEV catalog, apply the vendor updates as the required action.

Affected
VMware Fusion11.x before 11.5.2
VMware Remote Console for Mac (VMRC)11.x and prior before 11.0.1
VMware Horizon Client for Mac5.x and prior before 5.4.0
Estimated exposure
largehundreds of thousands of Mac endpoints with vulnerable versions of Fusion, VMRC for Mac, or Horizon Client for Mac installed (order-of-magnitude estimate) — Estimate based on VMware Fusion's long-standing mainstream installed base among Mac desktop users and the widespread enterprise deployment of Horizon Client for Mac, since no authoritative install counts are provided in the data; the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.

CISA Known Exploited Vulnerability
Affected
VMware Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
fusion, horizon client, remote console
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news