CVE detail
CVE-2020-3948 — CVE-2020-3948
Published 2020-03-16 · Modified 2026-06-17 · Vendor vmware · Product fusion · Source nvd
HIGH
severity
CVSS-derived band
0.0028
EPSS probability
exploitation probability, 30d
20.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privilege escalation vulnerability due to improper file permissions in Cortado Thinprint. Local attackers with non-administrative access to a Linux guest VM with virtual printing enabled may exploit this issue to elevate their privileges to root on the same guest VM.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References