Vulnerabilities > CVE-2018-6970 - Out-of-bounds Read vulnerability in VMWare Horizon Client and Horizon View

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
vmware
CWE-125
nessus

Summary

VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1) contain an out-of-bounds read vulnerability in the Message Framework library. Successfully exploiting this issue may allow a less-privileged user to leak information from a privileged process running on a system where Horizon Connection Server, Horizon Agent or Horizon Client are installed. Note: This issue doesn't apply to Horizon 6, 7 Agents installed on Linux systems or Horizon Clients installed on non-Windows systems.

Common Weakness Enumeration (CWE)

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Overread Buffers
    An adversary attacks a target by providing input that causes an application to read beyond the boundary of a defined buffer. This typically occurs when a value influencing where to start or stop reading is set to reflect positions outside of the valid memory location of the buffer. This type of attack may result in exposure of sensitive information, a system crash, or arbitrary code execution.

Nessus

  • NASL familyWindows
    NASL idVMWARE_HORIZON_VIEW_AGENT_VMSA-2018-0019.NASL
    descriptionThe VMware Horizon View Agent installed on the remote host is 6.x prior to 6.2.7 or 7.x prior to 7.5.1. It is, therefore, affected by an information disclosure vulnerability related to the Message Framework library.
    last seen2020-03-21
    modified2018-08-09
    plugin id111601
    published2018-08-09
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/111601
    titleVMware Horizon View Agent 6.x < 6.2.7 / 7.x < 7.5.1 Local Information Disclosure Vulnerability (VMSA-2018-0019)
  • NASL familyWindows
    NASL idVMWARE_HORIZON_VIEW_CLIENT_VMSA_2018_0019.NASL
    descriptionThe version of VMware Horizon View Client installed on the remote host is 4.x prior to 4.8.1. It is, therefore, affected by an unspecified information disclosure vulnerability related to the Message Framework library. Note that Nessus has not tested for these issues but has instead relied only on the application
    last seen2020-03-21
    modified2018-08-09
    plugin id111602
    published2018-08-09
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/111602
    titleVMware Horizon View Client 4.x < 4.8.1 Information Disclosure Vulnerability (VMSA-2018-0019)