First published: Fri Oct 23 2020(Updated: )
VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious attacker with local privileges on the machine where Horizon Client for Windows is installed may be able to retrieve hashed credentials if the client crashes.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Horizon Client | >=5.0.0<5.5.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-3998 is medium with a severity value of 6.5.
The affected software for CVE-2020-3998 is VMware Horizon Client for Windows (5.x prior to 5.5.0).
A malicious attacker with local privileges on the machine where Horizon Client for Windows is installed may be able to retrieve hashed credentials if the client crashes.
To fix CVE-2020-3998, update VMware Horizon Client for Windows to version 5.5.0 or newer.
You can find more information about CVE-2020-3998 on the VMware Security Advisories page at https://www.vmware.com/security/advisories/VMSA-2020-0024.html.