CVE-2020-3950
KEV PoC ×2largeSetuid-Based Local Privilege Escalation in VMware Fusion and Mac Clients
CISA: VMware Multiple Products Privilege Escalation Vulnerability
VMware Fusion, VMware Remote Console for Mac, and Horizon Client for Mac contain a local privilege escalation flaw (CWE-269, Improper Privilege Management) caused by improper use of setuid binaries, which run with elevated privileges when executed. An attacker who already has normal (non-root) user access to a Mac where one of these products is installed can invoke the misconfigured setuid binaries to execute code as root. Successful exploitation grants full root-level control over the affected machine, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Only macOS installations of Fusion 11.x before 11.5.2, VMRC for Mac 11.x and prior before 11.0.1, and Horizon Client for Mac 5.x and prior before 5.4.0 are affected. Public proof-of-concept exploits are available, and CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild; whether ransomware operators use it is unknown.
What to do: Upgrade affected Macs to VMware Fusion 11.5.2 or later, VMRC for Mac 11.0.1 or later, and Horizon Client for Mac 5.4.0 or later, per VMware's instructions. Because exploitation requires local user access, prioritize multi-user Macs and machines where untrusted users can execute code; inventory managed Macs for these products and verify installed versions. As the CVE is on the CISA KEV catalog, apply the vendor updates as the required action.
| VMware Fusion | 11.x before 11.5.2 |
| VMware Remote Console for Mac (VMRC) | 11.x and prior before 11.0.1 |
| VMware Horizon Client for Mac | 5.x and prior before 5.4.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.
- Affected
- VMware Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- vmware
- Products
- fusion, horizon client, remote console
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H