QID 376530

Date Published: 2022-04-13

QID 376530: VMware Horizon Client Privilege Escalation Vulnerability (VMSA-2022-0012)

VMware Horizon Client is software that allows you to connect your VMware Horizon virtual desktop to a device of choice, giving you on-the-go access from any location.

Affected Versions(s):
VMware Horizon Client 21.x before Build 2203
QID Detection Logic (authenticated):
This QID checks for vulnerable versions of Horizon via "vmware-installer" command.

A low-privileged malicious actor with local access to Horizon Client for Linux may be able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file.

  • CVSS V3 rated as Critical - 8.3 severity.
  • CVSS V2 rated as Critical - 8.7 severity.
  • Solution
    Information regarding the patches are published at VMSA-2022-0012.

    CVEs related to QID 376530

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0012 URL Logo www.vmware.com/security/advisories/VMSA-2022-0012.html