CVE-2020-3941
Last modified
CVE-2020-3941 is a high-severity vulnerability rated 7/10 on the CVSS scale. The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual Machine where Tools is installed. This vulnerability is not present in VMware Tools 11.x.y since the affected functionality is not present in VMware Tools 11.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual Machine where Tools is installed. This vulnerability is not present in VMware Tools 11.x.y since the affected functionality is not present in VMware Tools 11.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Tools | >= 10.0.0, < 11.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-3941?
How severe is CVE-2020-3941?
How do I fix CVE-2020-3941?
Are you affected by CVE-2020-3941?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
