Out-of-Bounds Read Vulnerability in VMware Workstation and Horizon View Client
CVE-2017-4948

7.1HIGH

Key Information:

Vendor
Vmware
Vendor
CVE Published:
5 January 2018

Summary

VMware Workstation and Horizon View Client have a vulnerability in TPView.dll that allows for information leaks and potential Denial of Service on the Windows OS. This occurs under specific circumstances, particularly if virtual printing is enabled. While this feature is disabled by default in Workstation, it is enabled by default in Horizon View, increasing its risk profile. Attackers may exploit this vulnerability in conjunction with other issues to gain unauthorized access to sensitive data or disrupt service, thus requiring immediate attention and remediation.

Affected Version(s)

Horizon Client for Windows 4.x before 4.7.0

Workstation 14.x before 14.1.0

Workstation 12.x

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.