CVE-2021-22000

HIGH

Vmware Thinapp < 5.2.10 - Uncontrolled Search Path

Title source: rule

Description

VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administrative privileges may exploit this vulnerability to elevate privileges to administrator level on the Windows operating system having VMware ThinApp installed on it.

Scores

CVSS v3 7.8
EPSS 0.0015
EPSS Percentile 35.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

vmware/thinapp < 5.2.10

Timeline

Published Jul 13, 2021
Tracked Since Feb 18, 2026