QID 376679

Date Published: 2022-06-27

QID 376679: VMware Horizon Connection Server Information Disclosure Vulnerability (VMSA-2019-0003)

Horizon Connection Server authenticates users through Windows Active Directory and directs the request to the appropriate virtual machine, physical PC, or Microsoft RDS host.

Affected Versions(s):
VMware Horizon Connection Server(CR) 7 prior to 7.8
VMware Horizon Connection Server 6 prior to 6.2.8
QID Detection Logic (authenticated):
This QID checks for vulnerable versions of Horizon Connection Server.

Successful exploitation of this issue may allow disclosure of internal domain names, the Connection Server's internal name, or the gateway's internal IP address.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Information regarding the patches are published at VMSA-2019-0003.

    CVEs related to QID 376679

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2019-0003 URL Logo www.vmware.com/security/advisories/VMSA-2019-0003.html