CVE-2019-5527
published 2019-10-10CVE-2019-5527: ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of…
PriorityP341high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.30%
22.2th percentile
ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | >= 11.0.0 < 11.5.0 | 11.5.0 |
| vmware | horizon | < 5.2.0 | 5.2.0 |
| vmware | remote_console | >= 10.0.0 < 10.0.5 | 10.0.5 |
| vmware | workstation | >= 15.0.0 < 15.5.0 | 15.5.0 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi, Workstation, Fusion, VMRC and Horizon Client updates address use-after-free and denial of service vulnerabilities. (CVE-2019-5527, CVE-2019-5535)
vendor_vmware·2019-09-19·CVSS 8.8
CVE-2019-5527 [HIGH] VMware ESXi, Workstation, Fusion, VMRC and Horizon Client updates address use-after-free and denial of service vulnerabilities. (CVE-2019-5527, CVE-2019-5535)
VMSA-2019-0014: VMware ESXi, Workstation, Fusion, VMRC and Horizon Client updates address use-after-free and denial of service vulnerabilities. (CVE-2019-5527, CVE-2019-5535)
| Advisory Severity | Important | CVSSv3 Range | 4.7-8.5 | Synopsis | VMware ESXi, Workstation, Fusion, VMRC and Horizon Client updates address use-after-free and denial of service vulnerabilities. (CVE-2019-5527, CVE-2019-5535) | Issue Date | 2019-09-19 | Updated On | 2019-09-21 | CVE(s) | CVE-2019-5527, CVE-2019-5535 VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation)
CVEs: CVE-2019-5527, CVE-2019-5535
Affected products: Fusion Pro, Horizon Client, VMware ESXi, VMware Fusion, VMware Horizon, VMware Workstation, VMware vSphere, Workstation Pro
GHSA
GHSA-r6hj-459q-h63h: ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device
ghsa_unreviewed·2022-05-24
CVE-2019-5527 [HIGH] CWE-416 GHSA-r6hj-459q-h63h: ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device
ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-10-10
Published