First published: Tue Apr 09 2019(Updated: )
VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosure vulnerability. Successful exploitation of this issue may allow disclosure of internal domain names, the Connection Server’s internal name, or the gateway’s internal IP address.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Horizon | >=6.0.0<6.2.8 | |
VMware Horizon | >=7.0<7.8 | |
VMware Horizon | >=7.5.0<7.5.2 | |
Microsoft Windows | ||
All of | ||
Any of | ||
VMware Horizon | >=6.0.0<6.2.8 | |
VMware Horizon | >=7.0<7.8 | |
VMware Horizon | >=7.5.0<7.5.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5513 is an information disclosure vulnerability found in VMware Horizon Connection Server.
The severity of CVE-2019-5513 is medium with a CVSS score of 5.3.
VMware Horizon Connection Server versions 6.x before 6.2.8 and versions 7.x before 7.8, 7.5.x before 7.5.2 are affected by CVE-2019-5513.
Successful exploitation of CVE-2019-5513 may allow disclosure of internal domain names, the Connection Server’s internal name, or the gateway’s internal IP address.
No, Microsoft Windows is not vulnerable to CVE-2019-5513.
You can find more information about CVE-2019-5513 on the VMware Security Advisories page: https://www.vmware.com/security/advisories/VMSA-2019-0003.html