cbcvebase.
CVE-2018-6971
published 2018-07-25

CVE-2018-6971: VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log…

high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (including silent installations). Successful exploitation of this issue may allow low privileged users access to the credentials specified during the Horizon View Agent installation.

Affected

11 ranges
VendorProductVersion rangeFixed in
vmwarefusion_pro
vmwarehorizon_view_agent
vmwarehorizon_view_agents>= 7.0.0 < 7.5.17.5.1
vmwarevmware_esxi
vmwarevmware_fusion
vmwarevmware_horizon
vmwarevmware_vrealize
vmwarevmware_vsphere
vmwarevmware_workstation
vmwareworkstation_player
vmwareworkstation_pro