Denial-of-Service Vulnerability in VMware Workstation and Horizon Client
CVE-2020-3951
3.8LOW
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 17 March 2020
Summary
VMware Workstation and Horizon Client for Windows are susceptible to a denial-of-service attack due to a heap overflow vulnerability in Cortado Thinprint. This issue allows attackers with non-administrative access to a guest VM with virtual printing enabled to exploit the weakness, potentially leading to a denial-of-service condition affecting the Thinprint service on the host system. Users of the affected versions should apply the latest updates to mitigate this risk.
Affected Version(s)
VMware Workstation and Horizon Client for Windows VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0)
References
CVSS V3.1
Score:
3.8
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved