Out-of-Bounds Read Vulnerability in VMware Horizon Products
CVE-2018-6970

6.5MEDIUM

Key Information:

Vendor
Vmware
Vendor
CVE Published:
7 August 2018

Summary

VMware Horizon software, including Horizon 6, Horizon 7, and Horizon Client, is susceptible to an out-of-bounds read vulnerability within its Message Framework library. This flaw could be exploited by a less-privileged user to gain unauthorized access to sensitive information from a privileged process running on the system. Note that this vulnerability does not affect Horizon Agents on Linux systems or Horizon Clients on non-Windows platforms, thereby limiting its impact within specific environments.

Affected Version(s)

VMware Horizon 6, Horizon 7, and Horizon Client VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1)

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.