Heap overflow in VMware Horizon Client and VMware Workstation - CVE-2020-3951

 

Heap overflow in VMware Horizon Client and VMware Workstation - CVE-2020-3951

Published: March 17, 2020


Vulnerability identifier: #VU26148
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3951
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within Cortado Thinprint. A local user can trigger heap overflow and crash the Thinprint service running on the system where Workstation or Horizon Client is installed.



Affected software

VMware Horizon Client
VMware Workstation

How to mitigate CVE-2020-3951

Install updates from vendor's website.

VMware Horizon Client - update to 5.4
VMware Workstation - update to 15.5.2

External References

Related Security Bulletins