| Vulnerability Name: | CVE-2017-4918 (CCN-127131) | ||||||||||||
| Assigned: | 2016-12-26 | ||||||||||||
| Published: | 2017-06-08 | ||||||||||||
| Updated: | 2017-07-08 | ||||||||||||
| Summary: | VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on the Mac OSX system where the client is installed. | ||||||||||||
| CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
| Vulnerability Type: | CWE-77 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2017-4918 Source: BID Type: Third Party Advisory, VDB Entry 98984 Source: CCN Type: BID-98984 VMware Horizon View Client CVE-2017-4918 Command Injection Vulnerability Source: SECTRACK Type: UNKNOWN 1038642 Source: XF Type: UNKNOWN vmware-cve20174918-command-exec(127131) Source: CCN Type: VMware Security Advisory VMSA-2017-0011 Horizon View Client update addresses a command injection vulnerability Source: CONFIRM Type: Vendor Advisory https://www.vmware.com/security/advisories/VMSA-2017-0011.html | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||