VYPR
Medium severity5.5NVD Advisory· Published May 31, 2017· Updated May 13, 2026

CVE-2017-4897

CVE-2017-4897

Description

VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sharing all their drives and devices. Successful exploitation of this vulnerability requires a victim to download a specially crafted RDP file through DaaS client by clicking on a malicious link.

Affected products

2
  • cpe:2.3:a:vmware:horizon_daas:*:*:*:*:*:*:*:*
    Range: <=6.1.6
  • VMware/Horizon DaaSv5
    Range: prior to 7.0.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.