Learn about CVE-2020-3961, a privilege escalation vulnerability in VMware Horizon Client for Windows (prior to 5.4.3) that allows local users to run commands as any user. Find mitigation steps and update information here.
VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability that allows a local user to run commands as any user.
Understanding CVE-2020-3961
This CVE identifies a privilege escalation vulnerability in VMware Horizon Client for Windows.
What is CVE-2020-3961?
CVE-2020-3961 is a security vulnerability in VMware Horizon Client for Windows (prior to 5.4.3) that arises from folder permission misconfiguration and unsafe library loading. It enables a local user to execute commands as any user on the system.
The Impact of CVE-2020-3961
The vulnerability allows unauthorized users to escalate their privileges and potentially perform malicious actions on the affected system.
Technical Details of CVE-2020-3961
VMware Horizon Client for Windows (prior to 5.4.3) is susceptible to privilege escalation due to the following:
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
To address CVE-2020-3961, consider the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates