CVE-2019-5524
published 2019-04-02CVE-2019-5524: VMware Workstation (14.x before 14.1.6) and Fusion (10.x before 10.1.6) contain an out-of-bounds write vulnerability in the e1000 virtual network adapter. This…
PriorityP354high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
4.12%
89.7th percentile
VMware Workstation (14.x before 14.1.6) and Fusion (10.x before 10.1.6) contain an out-of-bounds write vulnerability in the e1000 virtual network adapter. This issue may allow a guest to execute code on the host.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | fusion | >= 10.0.0 < 10.1.6 | 10.1.6 |
| vmware | workstation | >= 14.0.0 < 14.1.6 | 14.1.6 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-88f2-66g2-2qpg: VMware Workstation (14
ghsa_unreviewed·2022-05-14
CVE-2019-5524 [HIGH] CWE-787 GHSA-88f2-66g2-2qpg: VMware Workstation (14
VMware Workstation (14.x before 14.1.6) and Fusion (10.x before 10.1.6) contain an out-of-bounds write vulnerability in the e1000 virtual network adapter. This issue may allow a guest to execute code on the host.
VMware
VMware ESXi, Workstation and Fusion updates address multiple security issues.
vendor_vmware·2019-03-28·CVSS 6.8
CVE-2019-5514 [MEDIUM] VMware ESXi, Workstation and Fusion updates address multiple security issues.
VMSA-2019-0005: VMware ESXi, Workstation and Fusion updates address multiple security issues.
VMware ESXi, Workstation and Fusion updates address multiple security issues. 2. Relevant Products VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation) VMware Fusion Pro / Fusion (Fusion) 3. Problem Description a. VMware ESXi, Workstation and Fusion UHCI out-of-bounds read/write and TOCTOU vulnerabilities VMware ESXi, Workstation and Fusion contain an out-of-bounds read/write vulnerability and a Time-of-check Time-of-use (TOCTOU) vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of these issues requires an attacker to have access to a virtual machine with a virtual USB controller present. These issues may allow a guest to execute cod
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/152290/VMware-Security-Advisory-2019-0005.htmlhttp://www.securityfocus.com/bid/107635https://www.vmware.com/security/advisories/VMSA-2019-0005.htmlhttp://packetstormsecurity.com/files/152290/VMware-Security-Advisory-2019-0005.htmlhttp://www.securityfocus.com/bid/107635https://www.vmware.com/security/advisories/VMSA-2019-0005.html
2019-04-02
Published