Skip to content
COOEY

FAIL › dossier

horizoncloud

VENDOR

· dossier confidence 20%

Horizon Cloud has faced multiple critical security failures, including remote code execution vulnerabilities that have been exploited by attackers.

PROFILE
CategoryVendorWhat they doHorizon Cloud provides digital work platform services, including VDI and apps, to help teams stay productive from virtually anywhere. Websitehttps://… ↗
SECURITY POSTURE

The security posture of Horizon Cloud has been characterized by a series of internal failures, including critical vulnerabilities that have been exploited by remote attackers.

Notable failures
  • CVE-2024-38889 (critical [RCE0day])
  • CVE-2024-38887 (critical [RCE])
  • CVE-2024-38886 (critical)
Patterns: Repeated unpatched edge-device RCEs; SQL Injection vulnerabilities; Traffic Injection attacks
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2024-08-02 CVE-2024-38889 critical An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.
2024-08-02 CVE-2024-38887 critical An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges.
2024-08-02 CVE-2024-38886 critical An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.
Open questions: What is the current security posture of Horizon Cloud? · How has the company addressed the noted security failures?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-07 03:40:48.985203+00:00