6.9
CVSSv2

CVE-2021-22000

Published: 13/07/2021 Updated: 20/09/2021
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

VMware Thinapp version 5.x before 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administrative privileges may exploit this vulnerability to elevate privileges to administrator level on the Windows operating system having VMware ThinApp installed on it.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware thinapp

Exploits

VMware ThinApp suffered from a dll hijacking vulnerability ...

Mailing Lists

A few months ago I disclosed IBM(R) Db2(R) Windows client DLL Hijacking Vulnerability(0day) I found: seclistsorg/fulldisclosure/2021/Feb/73 In that post I mentioned the vulnerability did not get fully patched After I told IBM on hackerone that I disclosed it, hackerone asked me to delete the post, IBM apologized and fully patched the ...