First published: Fri Jan 05 2018(Updated: )
The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vRealize Operations for Horizon | >=6.0<6.5.1 | |
VMware vRealize Operations for Published Applications | >=6.1.0<6.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-4946 is considered to be of low severity but poses a significant risk due to the potential for privilege escalation.
To fix CVE-2017-4946, upgrade to VMware vRealize Operations for Horizon version 6.5.1 or later, and vRealize Operations for Published Applications version 6.5.1 or later.
CVE-2017-4946 affects VMware V4H and V4PA desktop agents in versions before 6.5.1.
Exploitation of CVE-2017-4946 allows low privileged Windows users to escalate their privileges to SYSTEM.
No, CVE-2017-4946 can be exploited without requiring any user interaction.