QID 376417
Date Published: 2022-02-17
QID 376417: VMware Horizon Connection Server Apache Log4j Remote Code Execution (RCE) Vulnerabilities (VMSA-2021-0028) (Log4Shell)
Horizon Connection Server authenticates users through Windows Active Directory and directs the request to the appropriate virtual machine, physical PC, or Microsoft RDS host.
Affected Versions(s):
VMware Horizon Connection Server 2111 before Build 19050221
VMware Horizon Connection Server 2006,2012,2103,2106
VMware Horizon Connection Server 7.13.1 before Build 19069458
VMware Horizon Connection Server 7.13.0
VMware Horizon Connection Server 7.10.0 - 7.10.2
VMware Horizon Connection Server 7.4.0-7.9.0
VMware Horizon Connection Server 7.11.0,7.12.0
QID Detection Logic (authenticated):
This QID checks for vulnerable versions of Horizon agent exe file.
A malicious actor with network access to an impacted VMware product may exploit this issue to gain full control of the target system.
Refer to KB87073 for more information.
- VMSA-2021-0028 -
www.vmware.com/security/advisories/VMSA-2021-0028.html
CVEs related to QID 376417
Advisory ID | Software | Component | Link |
---|---|---|---|
VMSA-2021-0028 |
![]() |