CVE-2019-5525

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
06/06/2019
Last modified:
10/06/2019

Description

VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues to execute code on the Linux host where Workstation is installed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* 15.0.0 (including) 15.1.0 (excluding)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*