Heap overflow in VMware Horizon Client and VMware Workstation - CVE-2020-3951
Published: March 17, 2020
Vulnerability identifier: #VU26148
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3951
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within Cortado Thinprint. A local user can trigger heap overflow and crash the Thinprint service running on the system where Workstation or Horizon Client is installed.
Affected software
VMware Horizon Client
VMware Workstation
VMware Workstation
How to mitigate CVE-2020-3951
Install updates from vendor's website.
VMware Horizon Client - update to 5.4
VMware Workstation - update to 15.5.2
VMware Workstation - update to 15.5.2