漏洞标题
N/A
漏洞描述信息
VMware Workstation(12.x之前版本)和Horizon View Client(4.x之前版本)在TPView.dll中的JPEG2000解析器中存在多个堆缓冲区溢出漏洞。在工作站上,这可能允许 guest 在运行工作站的Windows操作系统上执行代码或进行拒绝服务。在Horizon View Client的情况下,这可能允许在运行Horizon View Client的Windows操作系统上执行代码或进行拒绝服务。只有在虚拟打印被启用的情况下才能进行Exploitation。此功能在工作站上默认不启用,但在Horizon View上默认启用。
CVSS信息
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
VMware Workstation和Horizon View Client JPEG2000解析器缓冲区错误漏洞
漏洞描述信息
VMWare Workstation是美国威睿(VMware)公司的一套桌面虚拟计算机软件。该软件提供可以同时运行多个不同的操作系统的虚拟机功能。Horizon View Client是一个可以将用户设备连接到VMWare Horizon虚拟桌面的客户端。JPEG2000 parser是一个用于解析JPEG图片的解析器。 VMware Workstation 12.5.3之前的12.x版本和Horizon View Client 4.4.0之前的4.x版本中TPView.dll文件的JPEG2000解析器
CVSS信息
N/A
漏洞类别
授权问题