First published: Fri Oct 16 2020(Updated: )
VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system access control issue during install time. Successful exploitation of this issue may allow an attacker to overwrite certain admin privileged files through a symbolic link attack at install time. This will result into a denial-of-service condition on the machine where Horizon Client for Windows is installed.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Horizon | >=5.0.0<5.5.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3991 is classified as a denial-of-service vulnerability impacting VMware Horizon Client.
To remediate CVE-2020-3991, upgrade VMware Horizon Client to version 5.5.0 or later.
CVE-2020-3991 is caused by a file system access control issue during the installation of VMware Horizon Client.
VMware Horizon Client versions from 5.0.0 to before 5.5.0 are affected by CVE-2020-3991.
Yes, CVE-2020-3991 can potentially be exploited by an attacker through a symbolic link attack during install time.