CVE-2019-5519
published 2019-04-01CVE-2019-5519: VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7)…
PriorityP428medium6.8CVSS 3.0
AVPACLPRNUINSUCHIHAH
EPSS
1.00%
59.4th percentile
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain a Time-of-check Time-of-use (TOCTOU) vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this issue requires an attacker to have access to a virtual machine with a virtual USB controller present. This issue may allow a guest to execute code on the host.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | >= 10.0.0 < 10.1.6 | 10.1.6 |
| vmware | fusion | >= 11.0.0 < 11.0.3 | 11.0.3 |
| vmware | workstation | >= 14.0.0 < 14.1.7 | 14.1.7 |
| vmware | workstation | >= 15.0.0 < 15.0.4 | 15.0.4 |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi, Workstation and Fusion updates address multiple security issues.
vendor_vmware·2019-03-28·CVSS 6.8
CVE-2019-5514 [MEDIUM] VMware ESXi, Workstation and Fusion updates address multiple security issues.
VMSA-2019-0005: VMware ESXi, Workstation and Fusion updates address multiple security issues.
VMware ESXi, Workstation and Fusion updates address multiple security issues. 2. Relevant Products VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation) VMware Fusion Pro / Fusion (Fusion) 3. Problem Description a. VMware ESXi, Workstation and Fusion UHCI out-of-bounds read/write and TOCTOU vulnerabilities VMware ESXi, Workstation and Fusion contain an out-of-bounds read/write vulnerability and a Time-of-check Time-of-use (TOCTOU) vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of these issues requires an attacker to have access to a virtual machine with a virtual USB controller present. These issues may allow a guest to execute cod
GHSA
GHSA-93m3-v38w-pv5q: VMware ESXi (6
ghsa_unreviewed·2022-05-13
CVE-2019-5519 [HIGH] CWE-367 GHSA-93m3-v38w-pv5q: VMware ESXi (6
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain a Time-of-check Time-of-use (TOCTOU) vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this issue requires an attacker to have access to a virtual machine with a virtual USB controller present. This issue may allow a guest to execute code on the host.
No detection rules found.
No public exploits indexed.
http://packetstormsecurity.com/files/152290/VMware-Security-Advisory-2019-0005.htmlhttp://www.securityfocus.com/bid/107535http://www.securityfocus.com/bid/108443https://www.vmware.com/security/advisories/VMSA-2019-0005.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-19-420/http://packetstormsecurity.com/files/152290/VMware-Security-Advisory-2019-0005.htmlhttp://www.securityfocus.com/bid/107535http://www.securityfocus.com/bid/108443https://www.vmware.com/security/advisories/VMSA-2019-0005.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-19-420/
2019-04-01
Published