Categories: VMware

VMware Security Advisory (VMSA-2018-0019) For VMware Horizon 6 & 7 Customers

VMware just released Security Advisory VMSA-2018-0019 for customers who are using VMware Horizon v6 or v7 and the Horizon Client for Windows. As many of my readers are VMware Horizon customers, I thought I’d bring this to your attention in case you missed the official notifications from VMware.

Advisory Summary

Out-of-bounds read vulnerability in the Message Framework library.

Horizon 6, 7, and Horizon Client for Windows contains an out-of-bounds read vulnerability in the Message Framework library. Successfully exploiting this issue may allow a less-privileged user to leak information from a privileged process running on a system where Horizon Connection Server, Horizon Agent or Horizon Client are installed.

Note: This issue doesn’t apply to Horizon 6, 7 Agents installed on Linux systems or Horizon Clients installed on non-Windows systems.

Remediation Steps

  • VMware Horizon 7.x.x customer should update to Horizon 7.5.1
  • VMware Horizon 6.x.x customer should update to Horizon 6.2.7
  • Horizon Client for Windows users should update to 4.8.1

For further information and direct links to the patch downloads, visit the Security Advisory VMSA-2018-0019 page.

Simon Long

Share
Published by
Simon Long

Recent Posts

Google Cloud VMware Engine @ VMworld 2021

Another VMworld is upon us!!! Sadly, it's only virtual again this year. However, that does…

3 years ago

Google Cloud VMware Engine – Learning Resources

As part of my recent move to Google, I'm working on quickly getting up to…

3 years ago

Hey Google!

I am delighted to announce the next chapter in my career. Today is my first…

3 years ago

EP13 – Defending Remotely

In episode thirteen of The VCDX Podcast, I am joined by two special guests who…

3 years ago

Getting Started With Oracle Cloud VMware Solution (OCVS) – Migrating Workloads Using VMware HCX

In my recent ‘Getting started with Oracle Cloud VMware Solution (OVCS)’ post; Getting Started With…

3 years ago

Getting Started With Oracle Cloud VMware Solution (OCVS) – Connecting To An On-Premises Environment

In my recent ‘Getting started with Oracle Cloud VMware Solution (OVCS)’ post; Getting Started With…

3 years ago