#VU46757 Integer overflow in VMware Horizon Client and VMware Workstation - CVE-2020-3990 

 

#VU46757 Integer overflow in VMware Horizon Client and VMware Workstation - CVE-2020-3990

Published: September 16, 2020


Vulnerability identifier: #VU46757
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-3990
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
VMware Horizon Client
VMware Workstation
Software vendor:
VMware, Inc

Description

The vulnerability allows a remote attacker to gain access to sensitive information on the system.

The vulnerability exists due to integer overflow in Cortado ThinPrint component. A remote authenticated attacker can pass specially crafted data to the application, trigger integer overflow and gain access to sensitive information on the target system.


Remediation

Install updates from vendor's website.

External links