Executive brief
VMware Fusion, Remote Console, and Horizon Client for Mac contain a privilege escalation vulnerability due to the improper use of setuid binaries. A local attacker with normal user privileges can exploit this flaw to escalate their privileges to root on the affected macOS system.
Affected products
- VMware Fusion 11.x before 11.5.2
- VMware Remote Console (VMRC) for Mac 11.x and prior before 11.0.1
- VMware Horizon Client for Mac 5.x and prior before 5.4.0
Timeline
- 2020-03-12: advisory: Initial VMSA-2020-0005 advisory date (implied by reference)
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed