QID 376530
Date Published: 2022-04-13
QID 376530: VMware Horizon Client Privilege Escalation Vulnerability (VMSA-2022-0012)
VMware Horizon Client is software that allows you to connect your VMware Horizon virtual desktop to a device of choice, giving you on-the-go access from any location.
Affected Versions(s):
VMware Horizon Client 21.x before Build 2203
QID Detection Logic (authenticated):
This QID checks for vulnerable versions of Horizon via "vmware-installer" command.
A low-privileged malicious actor with local access to Horizon Client for Linux may be able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file.
Solution
Information regarding the patches are published at VMSA-2022-0012.
Vendor References
- VMSA-2022-0012 -
www.vmware.com/security/advisories/VMSA-2022-0012.html
CVEs related to QID 376530
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2022-0012 |
|