CVE-2020-3950: VMware Multiple Products Privilege Escalation Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 7.3% chance of exploitation in the next 30 days.
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.
Affected products
- VMware Fusion: from 11.0.0, before 11.5.2 (fixed in 11.5.2)
- VMware Horizon Client: from 5.0.0, before 5.4.0 (fixed in 5.4.0)
- VMware Remote Console: from 11.0.0, before 11.0.1 (fixed in 11.0.1)
Published 2020-03-17. Last modified 2026-06-17.