Vmware Horizon vulnerabilities

6 known vulnerabilities affecting vmware/horizon.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2022-22964HIGHCVSS 7.8fixed in 22032022-04-11
CVE-2022-22964 [HIGH] CVE-2022-22964: VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a u VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file.
nvd
CVE-2022-22962HIGHCVSS 7.8fixed in 22032022-04-11
CVE-2022-22962 [HIGH] CWE-59 CVE-2022-22962: VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is ab VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file.
nvd
CVE-2022-22938MEDIUMCVSS 6.5≥ 5.0.0, < 5.5.32022-01-28
CVE-2022-22938 [MEDIUM] CVE-2022-22938: VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contai VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a virtual machine or remote desktop may exploit this issue to trigger a denial-of-service condition in the Thin
nvd
CVE-2020-3997MEDIUMCVSS 5.4≥ 7.0, < 7.10.3≥ 7.11.0, < 7.13.02020-10-23
CVE-2020-3997 [MEDIUM] CWE-79 CVE-2020-3997: VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerab VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject malicious script which will be executed.
nvd
CVE-2019-5527HIGHCVSS 8.8fixed in 5.2.02019-10-10
CVE-2019-5527 [HIGH] CWE-416 CVE-2019-5527: ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the vir ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.
nvd
CVE-2019-5513MEDIUMCVSS 5.3≥ 6.0.0, < 6.2.8≥ 7.0, < 7.8+1 more2019-04-09
CVE-2019-5513 [MEDIUM] CVE-2019-5513: VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosure vulnerability. Successful exploitation of this issue may allow disclosure of internal domain names, the Connection Server’s internal name, or the gateway’s internal IP address.
nvd