CVE-2023-34037: Medium severity vmware horizon vulnerability
Published Aug 4, 2023
·Updated
VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests.
Affected Software
8 affected components
VMware Horizon Client=2006
VMware Horizon Client=2012
VMware Horizon Client=2103
VMware Horizon Client=2106
VMware Horizon Client=2111
VMware Horizon Client=2111.1
VMware Horizon Client=2203
VMware Horizon Client=2212
Event History
Aug 4, 2023
CVE Published
via MITRE·11:18 AM
Data Sourced
via MITRE·11:18 AM
DescriptionSeverityWeakness
Data Sourced
12:15 PM
Description
Frequently Asked Questions
1
What is CVE-2023-34037?
CVE-2023-34037 is a HTTP request smuggling vulnerability in VMware Horizon Server.
2
What is the severity of CVE-2023-34037?
The severity of CVE-2023-34037 is medium.
3
How does CVE-2023-34037 affect VMware Horizon Client?
CVE-2023-34037 affects VMware Horizon Client versions 2006, 2012, 2103, 2106, 2111, 2111.1, 2203, and 2212.
4
How can a malicious actor exploit CVE-2023-34037?
A malicious actor with network access can exploit CVE-2023-34037 by performing HTTP smuggle requests.
5
Is there a fix available for CVE-2023-34037?
Yes, VMware has released a security advisory with fixes for CVE-2023-34037. Please refer to the advisory for more details.