CVE Database
/

CVE-2018-6971

Back to search

CVE-2018-6971

Published: Jul 25, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (including silent installations). Successful exploitation of this issue may allow low privileged users access to the credentials specified during the Horizon View Agent installation.

VendorProductVersions

VMware

Horizon View Agent

affected
7.x.x before 7.5.1

References

1041357
vdb-entry
x_refsource_SECTRACK
104883
vdb-entry
x_refsource_BID
1041358
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now