CVE-2019-5521
published 2019-09-20CVE-2019-5521: VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (11.x before…
PriorityP350critical9.6CVSS 3.1
AVNACLPRLUINSCCHINAH
EPSS
1.63%
73.7th percentile
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain an out-of-bounds read vulnerability in the pixel shader functionality. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to create a denial-of-service condition on the host. Exploitation of this issue require an attacker to have access to a virtual machine with 3D graphics enabled. It is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | >= 10.0.0 < 10.1.6 | 10.1.6 |
| vmware | fusion | >= 11.0.0 < 11.0.3 | 11.0.3 |
| vmware | vmware_esxi | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | >= 14.0.0 < 14.1.6 | 14.1.6 |
| vmware | workstation | >= 15.0.0 < 15.0.3 | 15.0.3 |
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cphr-3j6j-hwcv: VMware ESXi (6
ghsa_unreviewed·2022-05-24
CVE-2019-5521 [CRITICAL] CWE-125 GHSA-cphr-3j6j-hwcv: VMware ESXi (6
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain an out-of-bounds read vulnerability in the pixel shader functionality. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to create a denial-of-service condition on the host. Exploitation of this issue require an attacker to have access to a virtual machine with 3D graphics enabled. It is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.
VMware
VMware ESXi, Workstation and Fusion updates address out-of-bounds read/write vulnerabilities (CVE-2019-5521, CVE-2019-5684)
vendor_vmware·2019-08-02·CVSS 9.6
CVE-2019-5521 [CRITICAL] VMware ESXi, Workstation and Fusion updates address out-of-bounds read/write vulnerabilities (CVE-2019-5521, CVE-2019-5684)
VMSA-2019-0012: VMware ESXi, Workstation and Fusion updates address out-of-bounds read/write vulnerabilities (CVE-2019-5521, CVE-2019-5684)
| Advisory Severity | Important | CVSSv3 Range | 6.3-8.5 | Synopsis | VMware ESXi, Workstation and Fusion updates address out-of-bounds read/write vulnerabilities (CVE-2019-5521, CVE-2019-5684) | Issue Date | 2019-08-02 | Updated On | 2019-08-02 (Initial Advisory) | CVE(s) | CVE-2019-5521, CVE-2019-5684 VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation)
CVEs: CVE-2019-5521, CVE-2019-5684
Affected products: Fusion Pro, VMware ESXi, VMware Fusion, VMware Workstation, VMware vSphere, Workstation Player, Workstation Pro
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple vulnerabilities in NVIDIA Windows GPU Display Driver, VMware ESXi, Workstation and Fusion
blogs_talos·2019-08-05·CVSS 9.6
[CRITICAL] Vulnerability Spotlight: Multiple vulnerabilities in NVIDIA Windows GPU Display Driver, VMware ESXi, Workstation and Fusion
Piotr Bania of Cisco Talos discovered these vulnerabilities.
### Executive summary VMware ESXi, Workstation and Fusion are affected by an out-of-bounds write vulnerability that can be triggered using a specially crafted shader file. This vulnerability can be triggered from a VMware guest, affecting the VMware host, leading to a crash (denial-of-service) of the vmware-vmx.exe process on the host (TALOS-2019-0757).
However, when the host/guest systems are using an NVIDIA graphics card, the VMware denial-of-service can be turned into a code execution vulnerability (leading to a VM escape), because of an
additional security issue present in NVIDIA's Windows GPU Display Driver (TALOS-2019-0779).
Moreover, two out-of-bounds write vulnerabilities that could lead to arbitrary code execution ha
Talos
Vulnerability Spotlight: Multiple vulnerabilities in NVIDIA Windows GPU Display Driver, VMware ESXi, Workstation and Fusion
blogs_talos·2019-08-05·CVSS 9.6
[CRITICAL] Vulnerability Spotlight: Multiple vulnerabilities in NVIDIA Windows GPU Display Driver, VMware ESXi, Workstation and Fusion
## Vulnerability Spotlight: Multiple vulnerabilities in NVIDIA Windows GPU Display Driver, VMware ESXi, Workstation and Fusion
Piotr Bania of Cisco Talos discovered these vulnerabilities.
## Executive summary VMware ESXi, Workstation and Fusion are affected by an out-of-bounds write vulnerability that can be triggered using a specially crafted shader file. This vulnerability can be triggered from a VMware guest, affecting the VMware host, leading to a crash (denial-of-service) of the vmware-vmx.exe process on the host (TALOS-2019-0757).
However, when the host/guest systems are using an NVIDIA graphics card, the VMware denial-of-service can be turned into a code execution vulnerability (leading to a VM escape), because of an
additional security issue present in NVIDIA's Windows GPU Disp
2019-09-20
Published