CVE-2022-22938
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/01/2022
Last modified:
04/02/2022
Description
VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a virtual machine or remote desktop may exploit this issue to trigger a denial-of-service condition in the Thinprint service running on the host machine where VMware Workstation or Horizon Client for Windows is installed.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | 16.0.0 (including) | 16.2.2 (excluding) |
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:horizon:*:*:*:*:*:windows:*:* | 5.0.0 (including) | 5.5.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page