#VU9928 Out-of-bounds read in VMware Horizon and VMware Workstation


Published: 2018-01-10

Vulnerability identifier: #VU9928

Vulnerability risk: Low

CVSSv3.1: 4.7 [CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2017-4948

CWE-ID: CWE-125

Exploitation vector: Local network

Exploit availability: No

Vulnerable software:
VMware Horizon
Server applications / Virtualization software
VMware Workstation
Client/Desktop applications / Virtualization software

Vendor: VMware, Inc

Description
The vulnerability allows an adjacent attacker to obtain potentially sensitive information or cause DoS condition on the target system.

The weakness exists due to an out-of-bounds memory read error in Cortado ThinPrint ('TPView.dll'). An adjacent attacker can read arbitrary data on the host system or cause the View desktop system to crash.

Mitigation
Update VMware Horizon View to version 4.7.0.
Update VMware Workstation to version 14.1.

Vulnerable software versions

VMware Horizon: 4.6.1, 4.5.0

VMware Workstation: 12.0.0 - 12.5.8


External links
http://www.vmware.com/security/advisories/VMSA-2018-0003.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability