PT-2018-17850 · Vmware · Horizon Agent+4

Publicado

2018-08-10

·

Atualizado

2018-10-15

·

CVE-2018-6970

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware Horizon 6 versions 6.x.x before 6.2.7 VMware Horizon 7 versions 7.x.x before 7.5.1 VMware Horizon Client versions 4.x.x and prior before 4.8.1
Description The issue is an out-of-bounds read vulnerability in the Message Framework library. This may allow a less-privileged user to leak information from a privileged process running on a system where Horizon Connection Server, Horizon Agent, or Horizon Client are installed. Note that this issue does not apply to Horizon 6, 7 Agents installed on Linux systems or Horizon Clients installed on non-Windows systems.
Recommendations For VMware Horizon 6 versions 6.x.x before 6.2.7, update to version 6.2.7 or later. For VMware Horizon 7 versions 7.x.x before 7.5.1, update to version 7.5.1 or later. For VMware Horizon Client versions 4.x.x and prior before 4.8.1, update to version 4.8.1 or later.

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-6970
ZDI-18-881

Produtos afetados

Horizon Agent
Horizon Connection Server
Vmware Horizon 6
Vmware Horizon 7
Vmware Horizon Client