VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-service vulnerability due to a heap-overflow issue in Cortado Thinprint. Attackers with non-administrative access to a guest VM with virtual printing enabled may exploit this issue to create a denial-of-service condition of the Thinprint service running on the system where Workstation or Horizon Client is installed.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.vmware.com/security/advisories/VMSA-2020-0005.html | vendor advisory |