CVE-2021-22000

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
13/07/2021
Last modified:
28/06/2022

Description

VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administrative privileges may exploit this vulnerability to elevate privileges to administrator level on the Windows operating system having VMware ThinApp installed on it.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:thinapp:*:*:*:*:*:*:*:* 5.2 (including) 5.2.10 (excluding)