ZeroHour
Cisco Talospublished ()ingested

Vulnerability Spotlight: Denial of service in VMWare Workstation 15

highVulnerability exploited in the wildimportance 60CVE-2019-5516

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-5516
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.

VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds vulnerability with the vertex shader functionality. Exploitation of this issue requires an attacker to have access to a virtual machine with 3D graphics enabled. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. The workaround for this issue involves disabling the 3D-acceleration feature. This feature is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.

NVD description · AI analysis pending
6.82%
  • vmware fusion
  • vmware workstation
  • vmware esxi
Full article234 words · extracted from blog.talosintelligence.com · click to collapse

Monday, April 15, 2019 11:47

Piotr Bania of Cisco Talos discovered this vulnerability.

Executive summary

VMware Workstation 15 contains an exploitable denial-of-service vulnerability. Workstation allows users to run multiple operating systems on a Linux or Windows PC. An attacker could trigger this particular vulnerability from VMware guest user mode to cause a denial-of-service condition through an out-of-bounds read. This vulnerability only affects Windows machines.

In accordance with our coordinated disclosure policy, Cisco Talos worked with VMware to ensure that these issues are resolved and that an update is available for affected customers.

Vulnerability details

VMware Workstation 15 vertex shader functionality denial-of-service vulnerability (TALOS-2018-0762/CVE-2019-5516)

An exploitable denial-of-service vulnerability exists in VMware Workstation 15. A specially crafted vertex shader can cause denial-of-service issues. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host, leading to a vmware-vmx.exe process crash on host.

Read the complete vulnerability advisory here for additional information.

Versions tested

Talos tested and confirmed that VMware Workstation 15 (15.0.2 build-10952284) with Windows 10 x64 as guestVM is affected by this vulnerability.

CoverageThe following SNORTⓇ rules will detect exploitation attempts. Note that additional rules may be released at a future date and current rules are subject to change pending additional vulnerability information. For the most current rule information, please refer to your Firepower Management Center or Snort.org.

Snort Rules: 49045, 49046

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/vmware-dos-vulnerability-april-19/