Vulnerabilities > CVE-2018-6970 - Out-of-bounds Read vulnerability in VMWare Horizon Client and Horizon View
Summary
VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1) contain an out-of-bounds read vulnerability in the Message Framework library. Successfully exploiting this issue may allow a less-privileged user to leak information from a privileged process running on a system where Horizon Connection Server, Horizon Agent or Horizon Client are installed. Note: This issue doesn't apply to Horizon 6, 7 Agents installed on Linux systems or Horizon Clients installed on non-Windows systems.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Common Attack Pattern Enumeration and Classification (CAPEC)
- Overread Buffers An adversary attacks a target by providing input that causes an application to read beyond the boundary of a defined buffer. This typically occurs when a value influencing where to start or stop reading is set to reflect positions outside of the valid memory location of the buffer. This type of attack may result in exposure of sensitive information, a system crash, or arbitrary code execution.
Nessus
NASL family Windows NASL id VMWARE_HORIZON_VIEW_AGENT_VMSA-2018-0019.NASL description The VMware Horizon View Agent installed on the remote host is 6.x prior to 6.2.7 or 7.x prior to 7.5.1. It is, therefore, affected by an information disclosure vulnerability related to the Message Framework library. last seen 2020-03-21 modified 2018-08-09 plugin id 111601 published 2018-08-09 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/111601 title VMware Horizon View Agent 6.x < 6.2.7 / 7.x < 7.5.1 Local Information Disclosure Vulnerability (VMSA-2018-0019) NASL family Windows NASL id VMWARE_HORIZON_VIEW_CLIENT_VMSA_2018_0019.NASL description The version of VMware Horizon View Client installed on the remote host is 4.x prior to 4.8.1. It is, therefore, affected by an unspecified information disclosure vulnerability related to the Message Framework library. Note that Nessus has not tested for these issues but has instead relied only on the application last seen 2020-03-21 modified 2018-08-09 plugin id 111602 published 2018-08-09 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/111602 title VMware Horizon View Client 4.x < 4.8.1 Information Disclosure Vulnerability (VMSA-2018-0019)