Out-of-Bounds Read Vulnerability in VMware Horizon Products
CVE-2018-6970
6.5MEDIUM
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 7 August 2018
Summary
VMware Horizon software, including Horizon 6, Horizon 7, and Horizon Client, is susceptible to an out-of-bounds read vulnerability within its Message Framework library. This flaw could be exploited by a less-privileged user to gain unauthorized access to sensitive information from a privileged process running on the system. Note that this vulnerability does not affect Horizon Agents on Linux systems or Horizon Clients on non-Windows platforms, thereby limiting its impact within specific environments.
Affected Version(s)
VMware Horizon 6, Horizon 7, and Horizon Client VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1)
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved