CVE-2020-3941
published 2020-01-15CVE-2020-3941: The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual Machine where Tools is…
PriorityP429high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.30%
21.4th percentile
The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual Machine where Tools is installed. This vulnerability is not present in VMware Tools 11.x.y since the affected functionality is not present in VMware Tools 11.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | tools | >= 10.0.0 < 11.0.0 | 11.0.0 |
| vmware | vmware_tools_for_windows | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hwqh-393p-ff66: The repair operation of VMware Tools for Windows 10
ghsa_unreviewed·2022-05-24
CVE-2020-3941 [MEDIUM] GHSA-hwqh-393p-ff66: The repair operation of VMware Tools for Windows 10
The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual Machine where Tools is installed. This vulnerability is not present in VMware Tools 11.x.y since the affected functionality is not present in VMware Tools 11.
VMware
VMware Tools workaround addresses a local privilege escalation vulnerability (CVE-2020-3941)
vendor_vmware·2020-01-14·CVSS 7.0
CVE-2020-3941 [HIGH] VMware Tools workaround addresses a local privilege escalation vulnerability (CVE-2020-3941)
VMSA-2020-0002: VMware Tools workaround addresses a local privilege escalation vulnerability (CVE-2020-3941)
The repair operation of VMware Tools for Windows has a race condition. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8.
CVEs: CVE-2020-3941
Affected products: VMware Tools
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-01-15
Published