Out-of-Bounds Read Vulnerability in VMware Workstation and Horizon Client
CVE-2021-21988
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 24 May 2021
Summary
VMware Workstation and Horizon Client for Windows are impacted by an out-of-bounds read vulnerability found in the Cortado ThinPrint component, specifically in the JPEG2000 Parser. When exploited by a malicious user who has access to a virtual machine or remote desktop session, this vulnerability can lead to unauthorized information disclosure from the TPView process. This issue exists in versions of VMware Workstation prior to 16.1.2 and Horizon Client for Windows prior to 5.5.2, highlighting the importance of keeping software updated to safeguard against potential exploitation.
Affected Version(s)
VMware Workstation Pro / Player (Workstation), VMware Horizon Client for Windows VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved