CVE-2022-22938

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/01/2022
Last modified:
04/02/2022

Description

VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a virtual machine or remote desktop may exploit this issue to trigger a denial-of-service condition in the Thinprint service running on the host machine where VMware Workstation or Horizon Client for Windows is installed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* 16.0.0 (including) 16.2.2 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:vmware:horizon:*:*:*:*:*:windows:*:* 5.0.0 (including) 5.5.3 (excluding)


References to Advisories, Solutions, and Tools