CVE-2019-5541
published 2019-11-20CVE-2019-5541: VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter…
PriorityP345critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
1.41%
69.7th percentile
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition on their own VM.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | fusion | >= 11.0.0 < 11.5.1 | 11.5.1 |
| vmware | workstation | >= 15.0.0 < 15.5.1 | 15.5.1 |
| vmware | workstation_and_fusion | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w3wx-jc54-pqp4: VMware Workstation (15
ghsa_unreviewed·2022-05-24
CVE-2019-5541 [MEDIUM] GHSA-w3wx-jc54-pqp4: VMware Workstation (15
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition on their own VM.
VMware
VMware Workstation and Fusion updates address multiple security vulnerabilities (CVE-2019-5540, CVE-2019-5541, CVE-2019-5542)
vendor_vmware·2019-11-12·CVSS 7.7
CVE-2019-5540 [HIGH] VMware Workstation and Fusion updates address multiple security vulnerabilities (CVE-2019-5540, CVE-2019-5541, CVE-2019-5542)
VMSA-2019-0021: VMware Workstation and Fusion updates address multiple security vulnerabilities (CVE-2019-5540, CVE-2019-5541, CVE-2019-5542)
| Advisory Severity | Important | CVSSv3 Range | 5.0-8.7 | Synopsis | VMware Workstation and Fusion updates address multiple security vulnerabilities (CVE-2019-5540, CVE-2019-5541, CVE-2019-5542) | Issue Date | 2019-11-12 | Updated On | 2019-11-12 (Initial Advisory) | CVE(s) | CVE-2019-5540, CVE-2019-5541, CVE-2019-5542 VMware Workstation Pro / Player (Workstation) VMware Fusion Pro / Fusion (Fusion)2. IntroductionVMware Workstation and Fusion contain multiple security vulnerabilities. Patches and workarounds are available to remediate these vulnerabilities in affected VMware products.
CVEs: CVE-2019-5540, CVE-2019-5541, CVE-2019-5542
Affected prod
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-11-20
Published