CVE-2017-4946: VMware vRealize Operations For Horizon

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM.

Affected products

  • VMware vRealize Operations For Horizon: from 6.0, before 6.5.1 (fixed in 6.5.1)
  • VMware vRealize Operations For Published Applications: from 6.1.0, before 6.5.1 (fixed in 6.5.1)

Published 2018-01-05. Last modified 2026-06-17.