LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-3950: VMware Multiple Products Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-3950 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate…

CVE-2020-3950 is a privilege-escalation vulnerability affecting several VMware products for macOS: Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac. It stems from improper use of setuid binaries and can allow an attacker who already has a foothold on the system to raise privileges to root. For IT and security teams this matters because local privilege escalation turns a limited compromise into full host control, enabling persistence, credential theft, and further movement inside virtualization or remote-desktop environments.

Public detail is limited to the products and weakness class described by CISA; exact affected builds, scores, and exploit mechanics must be confirmed against the vendor advisory. CISA’s required action is simply to apply updates per vendor instructions. Ransomware use of this CVE is not documented.

How it works

The weakness is classified as CWE-269 (Improper Privilege Management). Setuid binaries run with the privileges of their owner—commonly root—rather than the privileges of the user who invokes them. When those binaries are implemented or invoked incorrectly, an attacker who can execute code or influence their arguments as a lower-privileged user may cause them to perform privileged operations on the attacker’s behalf.

In practical terms, a local attacker who already has a standard user account on a Mac running one of the affected VMware clients can abuse the flawed setuid handling to obtain a root shell or equivalent elevated rights. No remote unauthenticated exploit path is described in the available summary; the attack assumes prior local access. Specific invocation methods or proof-of-concept details are not provided here and should not be assumed—consult the vendor advisory for any technical elaboration.

Am I affected? How to find it in your systems

These components typically appear on macOS endpoints used by developers, IT staff, or end users who need local virtual machines (Fusion), console access to remote VMs (VMRC), or VMware Horizon desktop sessions (Horizon Client for Mac). Inventory every Mac that has any of these packages installed.

How to remediate

Patch first. Apply the vendor-supplied updates for VMware Fusion, VMRC for Mac, and Horizon Client for Mac exactly as directed in the official advisory. CISA explicitly requires organizations to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be deployed, reduce the attack surface and increase detection.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities frequently precede broader breaches once an attacker has root. If you have reason to believe a host running the affected software was compromised before patching, treat it as a potential incident: isolate the system, preserve forensic evidence, rotate credentials that may have been accessible from that host, and hunt for lateral movement. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts appear in prior leaks.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · Multiple Products
WeaknessCWE-269
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities