CVE-2020-3961

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/06/2020
Last modified:
21/07/2021

Description

VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permission configuration and unsafe loading of libraries. A local user on the system where the software is installed may exploit this issue to run commands as any user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:horizon_client:*:*:*:*:*:*:*:* 5.4.3 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools