PT-2021-3631 · Vmware · Vmware Thinapp
Houjingyi
·
Published
2021-07-13
·
Updated
2021-09-20
·
CVE-2021-22000
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VMware ThinApp versions 5.x prior to 5.2.10
Description
The issue is related to insecure loading of DLLs, which can be exploited to elevate privileges. A malicious actor with non-administrative privileges may exploit this vulnerability to gain administrator-level access on a Windows operating system with VMware ThinApp installed.
Recommendations
For versions prior to 5.2.10, update to version 5.2.10 or later to resolve the issue. As a temporary workaround, consider restricting the loading of external DLLs to minimize the risk of exploitation.
Exploit
Fix
Improper Privilege Management
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vmware Thinapp