HIGH CISA KEV

CVE-2020-3950

CVSS v3

7.8

HIGH

EPSS Score

19.7%

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.

CISA Known Exploited Vulnerability

Date Added
11/3/2021
Patch Due Date
5/3/2022
Ransomware Use
Unknown

Technical details

Published
3/17/2020

Frequently asked questions

What is CVE-2020-3950?

VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.

Is CVE-2020-3950 actively exploited?

Yes. CVE-2020-3950 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 5/3/2022.

What is the CVSS score for CVE-2020-3950?

CVE-2020-3950 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2020-3950 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.