PT-2021-3631 · Vmware · Vmware Thinapp

Houjingyi

·

Published

2021-07-13

·

Updated

2021-09-20

·

CVE-2021-22000

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware ThinApp versions 5.x prior to 5.2.10
Description The issue is related to insecure loading of DLLs, which can be exploited to elevate privileges. A malicious actor with non-administrative privileges may exploit this vulnerability to gain administrator-level access on a Windows operating system with VMware ThinApp installed.
Recommendations For versions prior to 5.2.10, update to version 5.2.10 or later to resolve the issue. As a temporary workaround, consider restricting the loading of external DLLs to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03850
CVE-2021-22000

Affected Products

Vmware Thinapp