CVE-2017-4907: VMware Horizon View

Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.

VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.

Affected products

  • VMware Horizon View: version 6.0 only; version 6.0.2 only; version 6.1 only; version 6.1.1 only; version 6.2 only; version 6.2.1 only; …
  • VMware Unified Access Gateway: version 2.5 only; version 2.5.1 only; version 2.7 only; version 2.7.2 only; version 2.8 only

Published 2017-06-08. Last modified 2026-06-17.