CVE-2022-22938 is a denial-of-service vulnerability in the Cortado ThinPrint component of VMware Workstation (versions prior to 16.2.2) and Horizon Client for Windows (versions prior to 5.5.3). An authenticated attacker with access to a virtual machine or remote desktop can exploit a flaw in the TrueType font parser to crash the ThinPrint service on the host machine. This vulnerability has a CVSS score of 6.5 (Medium) and is rated as low complexity, requiring local user privileges to achieve a high impact denial-of-service. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.0.0, < 16.2.2CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.5.3CPE matchmatch criteria | cpe:2.3:a:vmware:horizon:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.