VMware Horizon

CPE: cpe:2.3:a:vmware:horizon:*:*:*:*:*:*:*:*
Patched Version: Unknown
Last Vulnerable Version: 8.4.0
First Vulnerable Version:

Vendor Data Exploit in the Wild Confirmed Vulnerable Vendor Patch Exists
Community Data Log4j Default Vulnerable Exploitable

Vendor Resources

Resource Link
VMSA-2021-0028.4 (vmware.com) https://www.vmware.com/security/advisories/VMSA-2021-0028.html
Advisory https://www.vmware.com/security/advisories/VMSA-2021-0028.html
Workarounds https://kb.vmware.com/s/article/87073

Community Resources

Resource Link
VMSA-2021-0028.1 (vmware.com) https://www.vmware.com/security/advisories/VMSA-2021-0028.html
VMware KB 87073 (vmware.com) https://kb.vmware.com/s/article/87073
Randori Advisory https://www.randori.com/blog/vmsa-2021-0028-vmware-log4shell-impact-remediations/

Community Notes

Source Note
NCSC-NL CVE-2021-44228: Fix ; CVE-2021-45046: Fix
CISAGov Last Update: 12/17/2021

Sources

Date Attribution Description
2021-12-29 18:59:51 NCSC-NL Updated vendorPatchExists. Updated community note. Updated community link VMSA-2021-0028.1 (vmware.com).
2021-12-30 21:31:50 CISAGov Updated communityVulnerable. Updated vendorPatchExists. Updated vendor link VMSA-2021-0028.4 (vmware.com). Updated community link VMware KB 87073 (vmware.com). Updated community note.
2021-12-13T14:07:00-07:00 Randori Updated cpe. Updated lastVulnerable. Updated vendorExploitInWild. Updated vendorConfirmedVulnerable. Updated communityLog4jDefault. Updated communityVulnerable. Updated communityExploitable. Updated community link Randori Advisory. Updated vendor link Advisory. Updated vendor link Workarounds.