Vulnerability Details CVE-2020-3961
VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permission configuration and unsafe loading of libraries. A local user on the system where the software is installed may exploit this issue to run commands as any user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 15.7%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 4.6
Products affected by CVE-2020-3961
-
cpe:2.3:a:vmware:horizon_client:-
-
cpe:2.3:a:vmware:horizon_client:4.0.0
-
cpe:2.3:a:vmware:horizon_client:4.0.1
-
cpe:2.3:a:vmware:horizon_client:4.1.0
-
cpe:2.3:a:vmware:horizon_client:4.2.0
-
cpe:2.3:a:vmware:horizon_client:4.3.0
-
cpe:2.3:a:vmware:horizon_client:4.4.0
-
cpe:2.3:a:vmware:horizon_client:4.5.0
-
cpe:2.3:a:vmware:horizon_client:4.6.0
-
cpe:2.3:a:vmware:horizon_client:4.6.1
-
cpe:2.3:a:vmware:horizon_client:4.7.0
-
cpe:2.3:a:vmware:horizon_client:4.8.0
-
cpe:2.3:a:vmware:horizon_client:4.8.1
-
cpe:2.3:a:vmware:horizon_client:5.0.0
-
cpe:2.3:a:vmware:horizon_client:5.1.0
-
cpe:2.3:a:vmware:horizon_client:5.2.0
-
cpe:2.3:a:vmware:horizon_client:5.3.0
-
cpe:2.3:a:vmware:horizon_client:5.4.0
-
cpe:2.3:o:microsoft:windows:-