PT-2020-2667 · Vmware+1 · Vmware Workstation+2
Dhanesh Kizhakkinan
·
Published
2020-03-17
·
Updated
2020-03-24
·
CVE-2020-3951
CVSS v3.1
3.8
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
VMware Workstation versions 15.x before 15.5.2
Horizon Client for Windows versions 5.x and prior before 5.4.0
Description
The issue is related to a heap-overflow problem in the Cortado Thinprint component, which can be exploited to create a denial-of-service condition. Attackers with non-administrative access to a guest VM with virtual printing enabled may exploit this issue to disrupt the Thinprint service.
Recommendations
For VMware Workstation versions 15.x before 15.5.2, update to version 15.5.2 or later.
For Horizon Client for Windows versions 5.x and prior before 5.4.0, update to version 5.4.0 or later.
As a temporary workaround, consider disabling the virtual printing feature in the guest VM to minimize the risk of exploitation.
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cortado Thinprint
Horizon Client For Windows
Vmware Workstation