CVE-2018-6971
VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (including silent installations). Successful exploitation of this issue may allow low privileged users access to the credentials specified during the Horizon View Agent installation.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.42% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- vmware/horizon view agents
- Source
- security@vmware.com
References
- http://www.securityfocus.com/bid/104883Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041357Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041358Third Party Advisory, VDB Entry
- https://www.vmware.com/security/advisories/VMSA-2018-0018.htmlVendor Advisory
- http://www.securityfocus.com/bid/104883Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041357Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041358Third Party Advisory, VDB Entry
- https://www.vmware.com/security/advisories/VMSA-2018-0018.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.