HomeSecurityVMware: Fixes critical vulnerabilities in Fusion, VMRC and other products

VMware: Fixes Critical Vulnerabilities in Fusion, VMRC, and Other Products

VMware released a new update security yesterday to fix two critical vulnerabilities that allow privilege escalation and denial-of-service (DoS) in attacks VMware Workstation, VMware Fusion, VMware Remote Console , and Horizon Client.

The two vulnerabilities are known as CVE-2020-3950 and CVE-2020-3951 and are due to the incorrect use of setuid binaries and a heap-overflow issue in Cortado Thinprint.

Vulnerabilities could lead to privilege escalation and DoS attacks

The vulnerability , CVE-2020-3950, was reported by Jeffball and Rich Mirch. VMware itself has stated that the vulnerability is very serious.

This vulnerability affects VMware Fusion (versions 11.x before 11.5.2), VMware Remote Console for Mac (all versions before 11.0.1), and Horizon Client for Mac (all versions before 5.4.0).

According to VMware, successful exploitation of this vulnerability could allow attackers to gain elevated privileges and root access to the system where Fusion, VMRC, or Horizon Client is installed.

On the other hand, the vulnerability that allows denial of service attackswas discovered in Cortado Thinprint and reported by Dhanesh Kizhakkinan of FireEye. This vulnerability affects VMware Workstation (versions 15.x before 15.5.2), Windows and Linux apps, as well as Horizon Client for Windows (all versions before 5.4. 0).

VMware

VMware says that attackers could create a denial of service condition in the service , which runs on the system where Workstation or Horizon Client is installed.

To fix the two vulnerabilities, you must obtain the security, which are located in the 'Fixed Version' column of the 'Resolution Matrix', which is available in the VMSA-2020-0005 advisory.

Critical Guest-to-Host DoS bug fixed last week

Last week, VMware patched another critical use-after-free vmnetdhcp vulnerability in VMware Workstation (versions 15.x before 15.5.2) and Fusion (versions 11.x before 11.5.2). The vulnerability could allow code execution on the host system and a denial of service attack.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS