VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows machine where Workstation or View Agent is installed.
2019-12-23T20:15:11.080
2024-11-21T04:45:09.370
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | horizon_view_agent | < 7.5.4 | Yes |
Application | vmware | horizon_view_agent | < 7.10.1 | Yes |
Application | vmware | workstation | < 15.5.1 | Yes |
Operating System | microsoft | windows | - | No |