Vulnerability Details CVE-2020-3957
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC and Horizon Client are installed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.1%
CVSS Severity
CVSS v3 Score 7.0
CVSS v2 Score 6.9
Products affected by CVE-2020-3957
-
cpe:2.3:a:vmware:fusion:11.0.0
-
cpe:2.3:a:vmware:fusion:11.0.1
-
cpe:2.3:a:vmware:fusion:11.0.2
-
cpe:2.3:a:vmware:fusion:11.0.3
-
cpe:2.3:a:vmware:fusion:11.1.0
-
cpe:2.3:a:vmware:fusion:11.1.1
-
cpe:2.3:a:vmware:fusion:11.5.0
-
cpe:2.3:a:vmware:fusion:11.5.1
-
cpe:2.3:a:vmware:fusion:11.5.2
-
cpe:2.3:a:vmware:fusion:11.5.3
-
cpe:2.3:a:vmware:horizon_client:-
-
cpe:2.3:a:vmware:horizon_client:4.0.0
-
cpe:2.3:a:vmware:horizon_client:4.0.1
-
cpe:2.3:a:vmware:horizon_client:4.1.0
-
cpe:2.3:a:vmware:horizon_client:4.2.0
-
cpe:2.3:a:vmware:horizon_client:4.3.0
-
cpe:2.3:a:vmware:horizon_client:4.4.0
-
cpe:2.3:a:vmware:horizon_client:4.5.0
-
cpe:2.3:a:vmware:horizon_client:4.6.0
-
cpe:2.3:a:vmware:horizon_client:4.6.1
-
cpe:2.3:a:vmware:horizon_client:4.7.0
-
cpe:2.3:a:vmware:horizon_client:4.8.0
-
cpe:2.3:a:vmware:horizon_client:4.8.1
-
cpe:2.3:a:vmware:horizon_client:5.0.0
-
cpe:2.3:a:vmware:horizon_client:5.1.0
-
cpe:2.3:a:vmware:horizon_client:5.2.0
-
cpe:2.3:a:vmware:horizon_client:5.3.0
-
cpe:2.3:a:vmware:horizon_client:5.4.0
-
cpe:2.3:a:vmware:remote_console:-
-
cpe:2.3:a:vmware:remote_console:1.5.0
-
cpe:2.3:a:vmware:remote_console:10.0.0
-
cpe:2.3:a:vmware:remote_console:10.0.1
-
cpe:2.3:a:vmware:remote_console:10.0.2
-
cpe:2.3:a:vmware:remote_console:10.0.3
-
cpe:2.3:a:vmware:remote_console:10.0.4
-
cpe:2.3:a:vmware:remote_console:10.0.5
-
cpe:2.3:a:vmware:remote_console:11.0.0
-
cpe:2.3:a:vmware:remote_console:11.0.1
-
cpe:2.3:a:vmware:remote_console:8.0.0
-
cpe:2.3:a:vmware:remote_console:8.1.0
-
cpe:2.3:a:vmware:remote_console:9.0.0
-