CVE-2020-3941 has been determined to affect VMware Tools on Windows version 10.x.y. This vulnerability and its impact on VMware products are documented in https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23569 Please review this advisory before continuing as there may be considerations outside the scope of this document.
The VMware Tools team has investigated CVE-2020-3941 and determined that the possibility of exploitation can be removed by performing the steps detailed in the Workaround section of this article.
VMware Tools 10.x
This issue is resolved in VMware Tools 11.0.0 and later.
Workaround:
To remediate this issue, it is recommended to upgrade VMware Tools to 11.0.0 or later.
However, if upgrading is not possible, exploitation of this issue can be prevented by correcting the ACLs on C:\ProgramData\VMware\VMware CAF directory in the Windows guests running VMware Tools 10.x.y versions. In order to correct ACLs for this directory, remove all write access permissions for Standard User from the directory.
To correct ACLs for this directory:
To request a new product feature, please contact your VMware representative.