← Vulnerability feed

Vulnerability record · CVE-2020-3950 · published 17 March 2020

CVE-2020-3950: VMware Fusion, VMRC and Horizon Client setuid privilege escalation

Vmware · Fusion

VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac mishandle setuid binaries, allowing a local user to gain root. The flaw affects Fusion 11.x before 11.5.2, VMRC before 11.0.1 and Horizon Client for Mac before 5.4.0. Because it yields full root on the host, it is a serious endpoint risk for Macs running these products.

7.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 7.3% · top 5.9% CWE-269 · Improper privilege management
7.8CVSS 3.1 base score, v2 7.2
7.3%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityLocal privilege escalation to root with public exploit code and CISA KEV listing, though it requires an existing low-privileged local account.

What it is

VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac mishandle setuid binaries, allowing a local user to gain root. The flaw affects Fusion 11.x before 11.5.2, VMRC before 11.0.1 and Horizon Client for Mac before 5.4.0. Because it yields full root on the host, it is a serious endpoint risk for Macs running these products.

Impact

An attacker with ordinary user privileges gains root on the system, giving full control of the host, including the ability to modify or disable security controls and access other users' data.

Attack surface

The attack is local (CVSS vector AV:L) and requires low privileges (PR:L) with no user interaction (UI:N); the attacker must already have a normal account on the machine and reach the vulnerable setuid binary.

Exploitation

CVE-2020-3950 is listed in CISA KEV with a 2022-05-03 remediation due date, and public exploit code is referenced on Packet Storm; EPSS 30-day probability is about 7.25 percent (94th percentile).

What to do

  • Upgrade Fusion to 11.5.2 or later, VMRC for Mac to 11.0.1 or later, and Horizon Client for Mac to 5.4.0 or later per VMSA-2020-0005.
  • If immediate patching is not possible, restrict local login and administrative rights on Macs running the affected products.
  • Audit setuid binaries installed by these products and remove or restrict any that are not required.
  • Monitor for unexpected root-level process creation or file changes originating from non-admin user sessions.

Detection

  • Alert on processes spawned by the VMware setuid binaries that run as root outside normal application behavior.
  • Monitor for privilege changes to uid 0 by non-admin users on hosts with Fusion, VMRC or Horizon Client installed.
  • Track endpoint inventory for unpatched versions of the three affected products.
  • Review system logs for suspicious setuid execution or tampering with the affected binaries.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-3950 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "VMware Multiple Products Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3950 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.0CVE-2025-22226VMware ESXi, Workstation and Fusion HGFS out-of-bounds read leaks vmx memoryVMware ESXi, Workstation, Fusion and related cloud products contain an out-of-bounds read in the HGFS (Host Guest File System) component. A malicious…KEVEPSS 1.7%analysed9.9CVE-2017-4901Vmware fusion memory buffer overflow vulnerabilityThe drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory acc…EPSS 20%9.6CVE-2019-5521Vmware fusion out-of-bounds read vulnerabilityVMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (1…EPSS 1.6%9.3CVE-2012-3288Vmware workstation improper input validation vulnerabilityVMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware…EPSS 3.8%9.3CVE-2011-3868Vmware workstation memory buffer overflow vulnerabilityBuffer overflow in VMware Workstation 7.x before 7.1.5, VMware Player 3.x before 3.1.5, VMware Fusion 3.1.x before 3.1.3, and VMware AMS allows remot…EPSS 5.8%9.1CVE-2019-5541Vmware workstation out-of-bounds write vulnerabilityVMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network ad…EPSS 1.4%9.0CVE-2012-2449Vmware workstation memory buffer overflow vulnerabilityVMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5…EPSS 2.5%9.0CVE-2012-2450Vmware workstation vulnerabilityVMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2020-3950), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.