Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-4897

Опубликовано: 31 мая 2017
Источник: nvd
CVSS3: 5.5
CVSS2: 7.1
EPSS Низкий

Описание

VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sharing all their drives and devices. Successful exploitation of this vulnerability requires a victim to download a specially crafted RDP file through DaaS client by clicking on a malicious link.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vmware:horizon_daas:*:*:*:*:*:*:*:*
Версия до 6.1.6 (включая)

EPSS

Процентиль: 30%
0.00111
Низкий

5.5 Medium

CVSS3

7.1 High

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.5
github
больше 3 лет назад

VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sharing all their drives and devices. Successful exploitation of this vulnerability requires a victim to download a specially crafted RDP file through DaaS client by clicking on a malicious link.

EPSS

Процентиль: 30%
0.00111
Низкий

5.5 Medium

CVSS3

7.1 High

CVSS2

Дефекты

CWE-20