Information disclosure in VMware Horizon - CVE-2018-6971
Published: July 23, 2018
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to the system logs authentication credentials in the 'vmmsi.log' log file when an account other than the current user account is specified during installation. A local attacker can view the passwords.
Affected software
VMware ESXi
VMware Fusion
VMware Workstation