CVE-2020-3998: Medium severity vmware horizon vulnerability
VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious attacker with local privileges on the machine where Horizon Client for Windows is installed may be able to retrieve hashed credentials if the client crashes.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3998?
The severity of CVE-2020-3998 is medium with a severity value of 6.5.
What is the affected software for CVE-2020-3998?
The affected software for CVE-2020-3998 is VMware Horizon Client for Windows (5.x prior to 5.5.0).
How can a malicious attacker exploit CVE-2020-3998?
A malicious attacker with local privileges on the machine where Horizon Client for Windows is installed may be able to retrieve hashed credentials if the client crashes.
How can I fix CVE-2020-3998?
To fix CVE-2020-3998, update VMware Horizon Client for Windows to version 5.5.0 or newer.
Where can I find more information about CVE-2020-3998?
You can find more information about CVE-2020-3998 on the VMware Security Advisories page at https://www.vmware.com/security/advisories/VMSA-2020-0024.html.