Horizon
Vendor:
First CVE: Apr 9, 2019 · Active for 7 years
6
Total CVEs
More Total CVEs than 80% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Horizon over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2019
7 years ago
Most Recent CVE
Apr 11, 2022
1,565 days ago
CVE Severity & Scoring
Horizon6 CVEs
50%
50%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local4 (66.7%)
Network2 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low5 (83.3%)
High0 (0.0%)
None1 (16.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22962HIGH VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic lin | Apr 11, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-22964HIGH VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file. | Apr 11, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-22938MEDIUM VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The iss | Jan 28, 2022 | 6.5 | 22 | NO | NO |
CVE-2019-5527HIGH ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the | Oct 10, 2019 | 8.8 | 21 | NO | NO |
CVE-2020-3997MEDIUM VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject mal | Oct 23, 2020 | 5.4 | 20 | NO | NO |
CVE-2019-5513MEDIUM VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosure vulnerability. Successful exploitation of this issue may | Apr 9, 2019 | 5.3 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Horizon
Top CWEs
Versions
No cataloged versions.