CVE-2019-5525
published 2019-06-06CVE-2019-5525: VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with…
PriorityP342high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
EPSS
0.44%
35.3th percentile
VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues to execute code on the Linux host where Workstation is installed.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vmware_workstation | — | — |
| vmware | workstation | >= 15.0.0 < 15.1.0 | 15.1.0 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Tools and Workstation updates address out of bounds read and use-after-free vulnerabilities. (CVE-2019-5522, CVE-2019-5525)
vendor_vmware·2019-06-06·CVSS 7.1
CVE-2019-5522 [HIGH] VMware Tools and Workstation updates address out of bounds read and use-after-free vulnerabilities. (CVE-2019-5522, CVE-2019-5525)
VMSA-2019-0009: VMware Tools and Workstation updates address out of bounds read and use-after-free vulnerabilities. (CVE-2019-5522, CVE-2019-5525)
| Advisory Severity | Important | CVSSv3 Range | 7.1-8.5 | Synopsis | VMware Tools and Workstation updates address out of bounds read and use-after-free vulnerabilities. (CVE-2019-5522, CVE-2019-5525) | Issue Date | 2019-06-06 | Updated On | 2019-06-06 (Initial Advisory) | CVE(s) | CVE-2019-5522, CVE-2019-5525 VMware Tools for Windows (VMware Tools) VMware Workstation Pro / Player for Linux (Workstation)
CVEs: CVE-2019-5522, CVE-2019-5525
Affected products: VMware Tools, VMware Workstation, Workstation Player, Workstation Pro
GHSA
GHSA-r6q4-gxv3-v7q7: VMware Workstation (15
ghsa_unreviewed·2022-05-24
CVE-2019-5525 [HIGH] CWE-416 GHSA-r6q4-gxv3-v7q7: VMware Workstation (15
VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues to execute code on the Linux host where Workstation is installed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-06-06
Published