Writeable Configuration Directory in VMware Horizon Client and VMware Workstation
CVE-2019-5543
7.8HIGH
Key Information:
- Vendor
- Vmware
- Status
- Vendor
- CVE Published:
- 16 March 2020
Summary
In certain versions of VMware Horizon Client, VMware Remote Console, and VMware Workstation for Windows, a vulnerability exists where the folder containing configuration files for the VMware USB arbitration service is set to writable by all users. This misconfiguration allows a local user to modify configurations and potentially execute commands as any user on the system where the software is installed, posing a risk of unauthorized access and system integrity compromise.
Affected Version(s)
VMware Horizon Client for Windows 5.x and prior before 5.3.0
VMware Remote Console for Windows 10.x before 11.0.0
VMware Workstation for Windows 15.x before 15.5.2
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved