CVE-2021-21987

Description

VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information disclosure from the TPView process running on the system where Workstation or Horizon Client for Windows is installed.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.178

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-21987,CVE-2021-21988,CVE-2021-21989 are affected in VMware Horizon Client (x64) 5.5.1Windows
Vulnerabilities CVE-2021-21987,CVE-2021-21988,CVE-2021-21989 are affected in VMware Horizon Client 5.5.1Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234