CISA Known Exploited Vulnerability

CVE-2020-3950

VMware · Multiple Products

VMware Multiple Products Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-269
Ransomware Unknown

CISA description

VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root.

Required action

Apply updates per vendor instructions.