ZeroHour

CVE-2019-5525

CVSS 3.0
8.8 high
EPSS
<1%p37
Published
()
Modified
Description

VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues to execute code on the Linux host where Workstation is installed.

Vendors
vmware
Products
workstation
Weakness
CWE-416
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news