CVE-2017-4918
Summary
| CVE | CVE-2017-4918 |
|---|---|
| State | PUBLISHED |
| Assigner | vmware |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-08 19:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on the Mac OSX system where the client is installed. |
Risk And Classification
Primary CVSS: v3.0 9.8 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-77 | Command injection vulnerability
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Horizon View | 2.0 | All | All | All |
| Application | Vmware | Horizon View | 2.1 | All | All | All |
| Application | Vmware | Horizon View | 2.2 | All | All | All |
| Application | Vmware | Horizon View | 2.3 | All | All | All |
| Application | Vmware | Horizon View | 3.0 | All | All | All |
| Application | Vmware | Horizon View | 3.1 | All | All | All |
| Application | Vmware | Horizon View | 3.2 | All | All | All |
| Application | Vmware | Horizon View | 3.3 | All | All | All |
| Application | Vmware | Horizon View | 4.0.0 | All | All | All |
| Application | Vmware | Horizon View | 4.0.1 | All | All | All |
| Application | Vmware | Horizon View | 4.1.0 | All | All | All |
| Application | Vmware | Horizon View | 4.2.0 | All | All | All |
| Application | Vmware | Horizon View | 4.3.0 | All | All | All |
| Application | Vmware | Horizon View | 4.4.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | VMware | Horizon View Client For Mac | affected 2.x | Not specified |
| CNA | VMware | Horizon View Client For Mac | affected 3.x | Not specified |
| CNA | VMware | Horizon View Client For Mac | affected 4.x prior to 4.5.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware Horizon View Client CVE-2017-4918 Command Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| VMware Horizon View Client for Mac Command Injection Bug Lets Local Users Obtain Root Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| VMSA-2017-0011 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.