QID 375939

Date Published: 2021-10-11

QID 375939: VMware App Volumes Local Privilege Escalation Vulnerability (VMSA-2021-0013)

VMware App Volumes is a portfolio of application and user management solutions for VMware Horizon,Citrix Virtual Apps and Desktops, and RDSH virtual environments.

Affected Versions:
VMware App Volumes for Windows 4.x versions prior to version 2103,Build 4.4.0.79
VMware App Volumes for Windows 2.x versions prior to 2.18.10.10

QID Detection Logic:(Authenticated)
It checks for vulnerable version of VMware App Volumes for Windows.

An attacker with normal access to a virtual machine may exploit this issue by placing a malicious file renamed as `openssl.cnf' in an unrestricted directory which would allow code to be executed with elevated privileges.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    To remediate this issue update to VMware App Volumes version VMware App Volumes 4, version 2103and VMware App Volumes 2.18.10
    For more information please visit VMware advisory VMSA-2021-0013

    CVEs related to QID 375939

    Software Advisories
    Advisory ID Software Component Link
    VMware App Volumes 2.18.10 URL Logo docs.vmware.com/en/VMware-App-Volumes/2.18.10/rn/VMware-App-Volumes-21810-Release-Notes.html
    VMware App Volumes 4, version 2103 URL Logo docs.vmware.com/en/VMware-App-Volumes/2103/rn/VMware-App-Volumes-4-version-2103.html