CVE-2020-3950 — VMware Multiple Products Privilege Escalation Vulnerability
2021-11-03 • CISA Known Exploited Vulnerability
[event] VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | VMware |
| Product | Multiple Products |
| CWE | CWE-269 |
| CVE ID | CVE-2020-3950 |
| Date Added | 2021-11-03 |
| Due Date | 2022-05-03 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2022-05-03