CVE-2019-5536
published 2019-10-28CVE-2019-5536: VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.12%
79.8th percentile
VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. Exploitation of this issue require an attacker to have access to a virtual machine with 3D graphics enabled. It is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | >= 11.0.0 < 11.5.0 | 11.5.0 |
| vmware | workstation | >= 15.0.0 < 15.5.0 | 15.5.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c3gx-v2m9-m8vc: VMware ESXi (6
ghsa_unreviewed·2022-05-24
CVE-2019-5536 [MEDIUM] CWE-20 GHSA-c3gx-v2m9-m8vc: VMware ESXi (6
VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. Exploitation of this issue require an attacker to have access to a virtual machine with 3D graphics enabled. It is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.
VMware
VMware ESXi, Workstation and Fusion updates address a denial-of-service vulnerability (CVE-2019-5536)
vendor_vmware·2019-10-24·CVSS 6.5
CVE-2019-5536 [MEDIUM] VMware ESXi, Workstation and Fusion updates address a denial-of-service vulnerability (CVE-2019-5536)
VMSA-2019-0019: VMware ESXi, Workstation and Fusion updates address a denial-of-service vulnerability (CVE-2019-5536)
| Advisory Severity | Moderate | Synopsis | VMware ESXi, Workstation and Fusion updates address a denial-of-service vulnerability (CVE-2019-5536) | Issue Date | 2019-10-24 | Updated On | 2019-10-24 (Initial Advisory) | CVE(s) | CVE-2019-5536 VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation)
CVEs: CVE-2019-5536
Affected products: Fusion Pro, VMware ESXi, VMware Fusion, VMware Workstation, VMware vSphere, Workstation Player, Workstation Pro
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Denial-of-service in VMWare Fusion 11
blogs_talos·2019-10-28·CVSS 6.5
[MEDIUM] Vulnerability Spotlight: Denial-of-service in VMWare Fusion 11
Piotr Bania of Cisco Talos discovered this vulnerability.
### Executive summary VMware Fusion 11 contains an exploitable denial-of-service vulnerability. VMWare Fusion is an application for Mac operating systems that allows users to run other OSs in a virtual environment, such as Windows and Linux. An attacker could exploit this vulnerability by supplying a malformed pixel shader inside of a VMware guest OS.
In accordance with our coordinated disclosure policy, Cisco Talos worked with VMware to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability detailsVMware Fusion 11 shader functionality denial-of-service (TALOS-2019-0848/CVE-2019-5536)
An exploitable denial-of-service vulnerability exists in VMware Fusion 11.1.0 (13668589).
Talos
Vulnerability Spotlight: Denial-of-service in VMWare Fusion 11
blogs_talos·2019-10-28·CVSS 6.5
[MEDIUM] Vulnerability Spotlight: Denial-of-service in VMWare Fusion 11
## Vulnerability Spotlight: Denial-of-service in VMWare Fusion 11
Piotr Bania of Cisco Talos discovered this vulnerability.
## Executive summary VMware Fusion 11 contains an exploitable denial-of-service vulnerability. VMWare Fusion is an application for Mac operating systems that allows users to run other OSs in a virtual environment, such as Windows and Linux. An attacker could exploit this vulnerability by supplying a malformed pixel shader inside of a VMware guest OS.
In accordance with our coordinated disclosure policy, Cisco Talos worked with VMware to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details VMware Fusion 11 shader functionality denial-of-service (TALOS-2019-0848/CVE-2019-5536)
An exploitable denial-o
2019-10-28
Published