CVE-2019-5516
published 2019-04-15CVE-2019-5516: VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before…
PriorityP337medium6.8CVSS 3.0
AVNACHPRLUINSUCHINAH
EPSS
1.67%
74.2th percentile
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds vulnerability with the vertex shader functionality. Exploitation of this issue requires an attacker to have access to a virtual machine with 3D graphics enabled. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. The workaround for this issue involves disabling the 3D-acceleration feature. This feature is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | fusion | >= 10.0.0 < 10.1.6 | 10.1.6 |
| vmware | fusion | >= 11.0.0 < 11.0.3 | 11.0.3 |
| vmware | workstation | — | — |
| vmware | workstation | — | — |
| vmware | workstation | >= 14.0.0 < 14.1.6 | 14.1.6 |
| vmware | workstation | >= 15.0.0 < 15.0.3 | 15.0.3 |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f2rq-wf7h-frf4: VMware ESXi (6
ghsa_unreviewed·2022-05-14
CVE-2019-5516 [MEDIUM] CWE-125 GHSA-f2rq-wf7h-frf4: VMware ESXi (6
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds vulnerability with the vertex shader functionality. Exploitation of this issue requires an attacker to have access to a virtual machine with 3D graphics enabled. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. The workaround for this issue involves disabling the 3D-acceleration feature. This feature is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.
VMware
VMware ESXi, Workstation and Fusion updates address multiple out-of-bounds read vulnerabilities.
vendor_vmware·2019-04-11·CVSS 6.8
CVE-2019-5516 [MEDIUM] VMware ESXi, Workstation and Fusion updates address multiple out-of-bounds read vulnerabilities.
VMSA-2019-0006: VMware ESXi, Workstation and Fusion updates address multiple out-of-bounds read vulnerabilities.
VMware ESXi, Workstation and Fusion updates address multiple out-of-bounds read vulnerabilities. 2. Relevant Products VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation) VMware Fusion Pro / Fusion (Fusion) 3. Problem Description a. VMware ESXi, Workstation and Fusion vertex shader out-of-bounds read vulnerability VMware ESXi, Workstation and Fusion updates address an out-of-bounds vulnerability with the vertex shader functionality. Exploitation of this issue requires an attacker to have access to a virtual machine with 3D graphics enabled. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privil
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Denial of service in VMWare Workstation 15
blogs_talos·2019-04-15·CVSS 6.8
[MEDIUM] Vulnerability Spotlight: Denial of service in VMWare Workstation 15
## Vulnerability Spotlight: Denial of service in VMWare Workstation 15
Piotr Bania of Cisco Talos discovered this vulnerability.
## Executive summary
VMware Workstation 15 contains an exploitable denial-of-service vulnerability. Workstation allows users to run multiple operating systems on a Linux or Windows PC. An attacker could trigger this particular vulnerability from VMware guest user mode to cause a denial-of-service condition through an out-of-bounds read. This vulnerability only affects Windows machines. In accordance with our coordinated disclosure policy, Cisco Talos worked with VMware to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details
VMware Workstation 15 vertex shader functionality denial-of-service vu
Talos
Vulnerability Spotlight: Denial of service in VMWare Workstation 15
blogs_talos·2019-04-15·CVSS 6.8
[MEDIUM] Vulnerability Spotlight: Denial of service in VMWare Workstation 15
Piotr Bania of Cisco Talos discovered this vulnerability.
### Executive summary
VMware Workstation 15 contains an exploitable denial-of-service vulnerability. Workstation allows users to run multiple operating systems on a Linux or Windows PC. An attacker could trigger this particular vulnerability from VMware guest user mode to cause a denial-of-service condition through an out-of-bounds read. This vulnerability only affects Windows machines.
In accordance with our coordinated disclosure policy, Cisco Talos worked with VMware to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability details
VMware Workstation 15 vertex shader functionality denial-of-service vulnerability (TALOS-2018-0762/CVE-2019-5516)
An exploitable denial-of
2019-04-15
Published