QID 372565
QID 372565: VMware Horizon DaaS OpenSLP Remote Code Execution Vulnerability (VMSA-2019-0022)
Horizon DaaS is a piece of software delivered by VMware to offer a multi-tenant VDI product used mainly by Service Providers.
OpenSLP as used in Horizon DaaS has a heap overwrite issue. A malicious actor with network access to port 427 on an ESXi host may be able to overwrite the heap of the OpenSLP service resulting in remote code execution.
Affected Versions:
VMWare Horizon DaaS 8.x prior to 9.0.0.0
Successful exploitation allows attacker to cause remote code execution
Solution
Vmware has released patch for VMware Horizon DaaS.
Refer to VMware advisory VMSA-2019-0022 for more information.
Refer to VMware advisory VMSA-2019-0022 for more information.
Vendor References
- VMSA-2019-0022 -
www.vmware.com/security/advisories/VMSA-2019-0022.html
CVEs related to QID 372565
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Horizon DaaS 9.0.0.0 |
|