QID 375600

Date Published: 2021-06-02

QID 375600: VMware Workstation and Horizon Client for Windows Multiple Vulnerabilities (VMSA-2021-0009)

VMware Workstation is a hosted hypervisor that runs on x64 versions of Windows and Linux operating systems. VMware Horizon is a commercial desktop and app virtualization product developed by VMware.

VMware Workstation and Horizon Client for Windows contain multiple out-of-bounds read vulnerabilities in Cortado ThinPrint component.

Affected Versions
VMware Workstation 16.x prior to 16.1.2
VMware Horizon Client for Windows 5.x prior to 5.5.2

QID Detection Logic (authenticated):
This QID checks for vulnerable versions of Workstation and Horizon Client for Windows.exe file.

A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    VMware has released patch Horizon Client for Windows
    Refer to VMware documents VMware Horizon Client 5.5.2 for more information.

    VMware has released the patch for Workstation.
    Refer to VMware documents VMware Workstation 16.1.2 for more information.

    CVEs related to QID 375600

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2021-0009 URL Logo www.vmware.com/security/advisories/VMSA-2021-0009.html