cbcvebase.
CVE-2019-5525
published 2019-06-06

CVE-2019-5525: VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with…

PriorityP342high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
EPSS
0.44%
35.3th percentile
VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues to execute code on the Linux host where Workstation is installed.

Affected

2 ranges
VendorProductVersion rangeFixed in
vmwarevmware_workstation
vmwareworkstation>= 15.0.0 < 15.1.015.1.0

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.