imPC@ndo IT

Tracker / CVE-2020-3988

CVE-2020-3988

Medium 6.1

VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (JPEG2000 parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.

Affected products and versions

vmware horizon_client · 5.0.0 → 5.4.4
vmware workstation_player · 15.0.0 → 16.0.0
vmware workstation_pro · 15.0.0 → 16.0.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References