CVE Database
/

CVE-2020-3990

Back to search

CVE-2020-3990

Published: Sep 16, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerability due to an integer overflow issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon Client.

VendorProductVersions

n/a

VMware Workstation and Horizon Client for Windows

affected
VMware Workstation (15.x), Horizon Client for Windows (5.x before 5.4.4)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now