Horizon Daas VMware Horizon Daas

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in VMware Horizon Daas.

By the Year

In 2026 there have been 0 vulnerabilities in VMware Horizon Daas. Horizon Daas did not have any published security vulnerabilities last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 1 6.50
2019 1 9.80
2018 1 0.00

It may take a day or so for new Horizon Daas vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent VMware Horizon Daas Security Vulnerabilities

VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication
CVE-2020-3977 6.5 - Medium - September 22, 2020

VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process. In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.

Missing Authentication for Critical Function

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue
CVE-2019-5544 9.8 - Critical - December 06, 2019

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

Memory Corruption

VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability
CVE-2018-6960 - April 20, 2018

VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.

VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data
CVE-2017-4897 - May 31, 2017

VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sharing all their drives and devices. Successful exploitation of this vulnerability requires a victim to download a specially crafted RDP file through DaaS client by clicking on a malicious link.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for VMware Horizon Daas or by VMware? Click the Watch button to subscribe.

VMware
Vendor

subscribe