CVE Database
/

CVE-2017-4948

Back to search

CVE-2017-4948

Published: Jan 5, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll. On Workstation, this issue in conjunction with other bugs may allow a guest to leak information from host or may allow for a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this issue in conjunction with other bugs may allow a View desktop to leak information from host or may allow for a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.

VendorProductVersions

VMware

Workstation

affected
14.x before 14.1.0
affected
12.x

VMware

Horizon Client for Windows

affected
4.x before 4.7.0

References

1040109
vdb-entry
x_refsource_SECTRACK
1040108
vdb-entry
x_refsource_SECTRACK
102441
vdb-entry
x_refsource_BID
1040136
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now