CVE-2019-5527

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
10/10/2019
Last modified:
02/06/2022

Description

ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:horizon:*:*:*:*:*:linux:*:* 5.2.0 (excluding)
cpe:2.3:a:vmware:horizon:*:*:*:*:*:macos:*:* 5.2.0 (excluding)
cpe:2.3:a:vmware:horizon:*:*:*:*:*:windows:*:* 5.2.0 (excluding)
cpe:2.3:a:vmware:remote_console:*:*:*:*:*:linux:*:* 10.0.0 (including) 10.0.5 (excluding)
cpe:2.3:a:vmware:remote_console:*:*:*:*:*:windows:*:* 10.0.0 (including) 10.0.5 (excluding)
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* 15.0.0 (including) 15.5.0 (excluding)
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* 11.0.0 (including) 11.5.0 (excluding)
cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.0:-:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.0:1:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.0:1a:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.0:1b:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.0:2:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.0:3:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.0:3a:*:*:*:*:*:*


References to Advisories, Solutions, and Tools