Loading
VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sharing all their drives and devices. Successful exploitation of this vulnerability requires a victim to download a specially crafted RDP file through DaaS client by clicking on a malicious link.
Use CWE-20, Vmware vendor hub and Horizon Daas product page to widen CVE-2017-4897 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-5544, CVE-2018-6960 and CVE-2020-3977 for nearby disclosures in the same product family.