CVE-2020-3948

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/03/2020
Last modified:
21/07/2021

Description

Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privilege escalation vulnerability due to improper file permissions in Cortado Thinprint. Local attackers with non-administrative access to a Linux guest VM with virtual printing enabled may exploit this issue to elevate their privileges to root on the same guest VM.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* 11.0.0 (including) 11.5.2 (excluding)
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* 15.0.0 (including) 15.5.2 (excluding)


References to Advisories, Solutions, and Tools