← Back

CVE-2020-3957

nvd nist
Published: May 29, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.0
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.0 / Impact: 5.9
Source: NVD

Description

VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC and Horizon Client are installed.

Affected (3)

3 products
Fusion
Horizon Client
Remote Console
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 11.0.0 to 11.5.5
Up to 5.4.0
Up to 11.0.1
Running on/withPlatform Versions
Apple
Macos
All versions

References (2)

Source: security@vmware.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.