CVE-2024-11467

HIGH

Omnissa Horizon Client - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-11467. PoCs published by null-event.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2024-11467, focusing on the VMware Horizon Client's privileged helper tool (com.vmware.horizon.CDSHelper) and its XPC service implementation. It includes reverse engineering insights, decompiled code snippets, and an explanation of the vulnerability's root cause.

Description

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.

Exploits (1)

nomisec WRITEUP
by null-event · poc
https://github.com/null-event/CVE-2024-11467

This repository provides a detailed technical analysis of CVE-2024-11467, focusing on the VMware Horizon Client's privileged helper tool (com.vmware.horizon.CDSHelper) and its XPC service implementation. It includes reverse engineering insights, decompiled code snippets, and an explanation of the vulnerability's root cause.

Classification
Writeup 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Theoretical
Target: VMware Horizon Client (specific version not specified)
No auth needed
Prerequisites: Access to a macOS system with VMware Horizon Client installed · Privileged helper tool (com.vmware.horizon.CDSHelper) must be present
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0018
EPSS Percentile 7.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
Omnissa/Omnissa Horizon Client for MacOS Omnissa Horizon Client for macOS 2406 or earlier
Published Feb 04, 2025
Tracked Since Feb 18, 2026