CVE-2018-6964: High severity VMware Horizon Client vulnerability
VMware Horizon Client for Linux (4.x before 4.8.0 and prior) contains a local privilege escalation vulnerability due to insecure usage of SUID binary. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on a Linux machine where Horizon Client is installed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VMware Horizon Client for Linuxto a version that resolves this vulnerability.Fixed in 4.8.0
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-6964.
What is the severity of CVE-2018-6964?
The severity of CVE-2018-6964 is high with a severity value of 7.8.
What is the affected software?
The affected software is VMware Horizon Client for Linux (4.x before 4.8.0 and prior).
What is the risk of this vulnerability?
The risk of this vulnerability is a local privilege escalation.
How can the vulnerability be exploited?
The vulnerability can be exploited by unprivileged users to escalate their privileges to root on a Linux machine where Horizon Client is installed.