CVE-2019-5539
published 2019-12-23CVE-2019-5539: VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.43%
34.6th percentile
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows machine where Workstation or View Agent is installed.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | horizon_view_agent | — | — |
| vmware | horizon_view_agent | — | — |
| vmware | horizon_view_agent | >= 7.10.0 < 7.10.1 | 7.10.1 |
| vmware | horizon_view_agent | >= 7.5.0 < 7.5.4 | 7.5.4 |
| vmware | vmware_workstation | — | — |
| vmware | workstation | >= 15.0.0 < 15.5.1 | 15.5.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r6qv-pq43-h5wg: VMware Workstation (15
ghsa_unreviewed·2022-05-24
CVE-2019-5539 [MEDIUM] CWE-426 GHSA-r6qv-pq43-h5wg: VMware Workstation (15
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows machine where Workstation or View Agent is installed.
VMware
VMware Workstation and Horizon View Agent updates address a DLL-hijacking issue (CVE-2019-5539)
vendor_vmware·2019-12-20·CVSS 7.8
CVE-2019-5539 [HIGH] VMware Workstation and Horizon View Agent updates address a DLL-hijacking issue (CVE-2019-5539)
VMSA-2019-0023: VMware Workstation and Horizon View Agent updates address a DLL-hijacking issue (CVE-2019-5539)
| Advisory Severity | Moderate | Synopsis | VMware Workstation and Horizon View Agent updates address a DLL-hijacking issue (CVE-2019-5539) | Issue Date | 2019-12-20 | Updated On | 2019-12-20 (Initial Advisory) | CVE(s) | CVE-2019-5539 VMware Workstation Pro / Player (Workstation) VMware Horizon View Agent (View Agent) 2. IntroductionVMware Workstation and Horizon View Agent contain a DLL-hijacking issue. Patches are available to remediate this vulnerability in affected VMware products.
CVEs: CVE-2019-5539
Affected products: VMware Horizon, VMware Workstation, Workstation Player, Workstation Pro
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-12-23
Published