cbcvebase.
CVE-2018-6971
published 2018-07-25

CVE-2018-6971: VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log…

PriorityP335high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.42%
33.8th percentile
VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (including silent installations). Successful exploitation of this issue may allow low privileged users access to the credentials specified during the Horizon View Agent installation.

Affected

11 ranges
VendorProductVersion rangeFixed in
vmwarefusion_pro
vmwarehorizon_view_agent
vmwarehorizon_view_agents>= 7.0.0 < 7.5.17.5.1
vmwarevmware_esxi
vmwarevmware_fusion
vmwarevmware_horizon
vmwarevmware_vrealize
vmwarevmware_vsphere
vmwarevmware_workstation
vmwareworkstation_player
vmwareworkstation_pro

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.