Vulnerability record · CVE-2020-3950 · published 17 March 2020
CVE-2020-3950: VMware Fusion, VMRC and Horizon Client setuid privilege escalation
Vmware · Fusion
VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac mishandle setuid binaries, allowing a local user to gain root. The flaw affects Fusion 11.x before 11.5.2, VMRC before 11.0.1 and Horizon Client for Mac before 5.4.0. Because it yields full root on the host, it is a serious endpoint risk for Macs running these products.
Description
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityLocal privilege escalation to root with public exploit code and CISA KEV listing, though it requires an existing low-privileged local account.
What it is
VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac mishandle setuid binaries, allowing a local user to gain root. The flaw affects Fusion 11.x before 11.5.2, VMRC before 11.0.1 and Horizon Client for Mac before 5.4.0. Because it yields full root on the host, it is a serious endpoint risk for Macs running these products.
Impact
An attacker with ordinary user privileges gains root on the system, giving full control of the host, including the ability to modify or disable security controls and access other users' data.
Attack surface
The attack is local (CVSS vector AV:L) and requires low privileges (PR:L) with no user interaction (UI:N); the attacker must already have a normal account on the machine and reach the vulnerable setuid binary.
Exploitation
CVE-2020-3950 is listed in CISA KEV with a 2022-05-03 remediation due date, and public exploit code is referenced on Packet Storm; EPSS 30-day probability is about 7.25 percent (94th percentile).
What to do
- Upgrade Fusion to 11.5.2 or later, VMRC for Mac to 11.0.1 or later, and Horizon Client for Mac to 5.4.0 or later per VMSA-2020-0005.
- If immediate patching is not possible, restrict local login and administrative rights on Macs running the affected products.
- Audit setuid binaries installed by these products and remove or restrict any that are not required.
- Monitor for unexpected root-level process creation or file changes originating from non-admin user sessions.
Detection
- Alert on processes spawned by the VMware setuid binaries that run as root outside normal application behavior.
- Monitor for privilege changes to uid 0 by non-admin users on hosts with Fusion, VMRC or Horizon Client installed.
- Track endpoint inventory for unpatched versions of the three affected products.
- Review system logs for suspicious setuid execution or tampering with the affected binaries.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-3950 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "VMware Multiple Products Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/156843/VMware-Fusion-11.5.2-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/157079/VMware-Fusion-USB-Arbitrator-Setuid-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.vmware.com/security/advisories/VMSA-2020-0005.html | Vendor Advisory |
| http://packetstormsecurity.com/files/156843/VMware-Fusion-11.5.2-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/157079/VMware-Fusion-USB-Arbitrator-Setuid-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.vmware.com/security/advisories/VMSA-2020-0005.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3950 | US Government Resource |
Track CVE-2020-3950 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-3950), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.