Denial-of-Service Vulnerability in VMware Workstation and Horizon Client
CVE-2020-3951

3.8LOW

Key Information:

Vendor
Vmware
Vendor
CVE Published:
17 March 2020

Summary

VMware Workstation and Horizon Client for Windows are susceptible to a denial-of-service attack due to a heap overflow vulnerability in Cortado Thinprint. This issue allows attackers with non-administrative access to a guest VM with virtual printing enabled to exploit the weakness, potentially leading to a denial-of-service condition affecting the Thinprint service on the host system. Users of the affected versions should apply the latest updates to mitigate this risk.

Affected Version(s)

VMware Workstation and Horizon Client for Windows VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0)

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.