ZeroHour
Security Affairspublished ()ingested @securityaffairs

VMware fixes Fusion flaw introduced in the attempt to fix CVE-2020

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3950
Setuid-Based Local Privilege Escalation in VMware Fusion and Mac Clients

VMware Fusion, VMware Remote Console for Mac, and Horizon Client for Mac contain a local privilege escalation flaw (CWE-269, Improper Privilege Management) caused by improper use of setuid binaries, which run with elevated privileges when executed. An attacker who already has normal (non-root) user access to a Mac where one of these products is installed can invoke the misconfigured setuid binaries to execute code as root. Successful exploitation grants full root-level control over the affected machine, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Only macOS installations of Fusion 11.x before 11.5.2, VMRC for Mac 11.x and prior before 11.0.1, and Horizon Client for Mac 5.x and prior before 5.4.0 are affected. Public proof-of-concept exploits are available, and CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild; whether ransomware operators use it is unknown.

Do: Upgrade affected Macs to VMware Fusion 11.5.2 or later, VMRC for Mac 11.0.1 or later, and Horizon Client for Mac 5.4.0 or later, per VMware's instructions. Because exploitation requires local user access, prioritize multi-user Macs and machines where untrusted users can execute code; inventory managed Macs for these products and verify installed versions. As the CVE is on the CISA KEV catalog, apply the vendor updates as the required action.

7.87% KEV PoC ×2
  • VMware Fusion 11.x before 11.5.2
  • VMware Remote Console for Mac (VMRC) 11.x and prior before 11.0.1
  • VMware Horizon Client for Mac 5.x and prior before 5.4.0
largehundreds of thousands of Mac endpoints with vulnerable versions of Fusion, VMRC for Mac, or Horizon Client for Mac installed (order-of-magnitude estimate)
CVE-2020-3957
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege e

VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC and Horizon Client are installed.

NVD description · AI analysis pending
7.0<1%
  • vmware fusion
  • vmware horizon client
  • vmware remote console
Full article235 words · extracted from securityaffairs.com · click to collapse

VMware has released an update to address a privilege escalation flaw in VMware for the macOS version of Fusion that was introduced by a previous patch.

In March, VMware patched a high-severity privilege escalation vulnerability (CVE-2020-3950) in Fusion, Remote Console (VMRC) and Horizon Client for Mac.

The CVE-2020-3950 is a privilege escalation vulnerability caused by the improper use of setuid binaries, it could be exploited by attackers to escalate privileges to root.

The flaw was reported by Jeffball of GRIMM and Rich Mirch, VMware assigned it a CVSSv3 base score of 7.3 and rated it as Important severity. The issue impacts Fusion (11.x before 11.5.2), Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) macOS apps.

Mirch and Jeffball, immediately noted that the patch issued by VMware was incomplete, VMware confirmed it a few days later and released a new patch at the end of March. Unfortunately the new fix introduced a new security issue.

The vulnerability introduced by the second patch, tracked as CVE-2020-3957, is a time-of-check time-of-use (TOCTOU) issue that could allow attackers with low permissions to execute arbitrary code with root privileges.

Last week, the company releases version 11.5.5, but the issue for VMRC and Horizon Client for Mac are yet to be approved.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Fusion, cybersecurity)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/104129/security/vmware-flaw-2020-3950.html