CVE-2020-3957 - CVE House
Back to Database
Status published High CVE-2020-3957

VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac...

Vulnerability Description

VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC and Horizon Client are installed.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-3957

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

VMware Fusion, VMware Remote Console for Mac, VMware Horizon Client for Mac
Vulnerable Versions:
11.x before 11.5.5, V11.x and prior, 5.x and prior

Timeline

Official Publish: May 29th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.