CVE-2019-5527
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
10/10/2019
Last modified:
02/06/2022
Description
ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vmware:horizon:*:*:*:*:*:linux:*:* | 5.2.0 (excluding) | |
| cpe:2.3:a:vmware:horizon:*:*:*:*:*:macos:*:* | 5.2.0 (excluding) | |
| cpe:2.3:a:vmware:horizon:*:*:*:*:*:windows:*:* | 5.2.0 (excluding) | |
| cpe:2.3:a:vmware:remote_console:*:*:*:*:*:linux:*:* | 10.0.0 (including) | 10.0.5 (excluding) |
| cpe:2.3:a:vmware:remote_console:*:*:*:*:*:windows:*:* | 10.0.0 (including) | 10.0.5 (excluding) |
| cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | 15.0.0 (including) | 15.5.0 (excluding) |
| cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* | 11.0.0 (including) | 11.5.0 (excluding) |
| cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:vmware:esxi:6.0:-:*:*:*:*:*:* | ||
| cpe:2.3:o:vmware:esxi:6.0:1:*:*:*:*:*:* | ||
| cpe:2.3:o:vmware:esxi:6.0:1a:*:*:*:*:*:* | ||
| cpe:2.3:o:vmware:esxi:6.0:1b:*:*:*:*:*:* | ||
| cpe:2.3:o:vmware:esxi:6.0:2:*:*:*:*:*:* | ||
| cpe:2.3:o:vmware:esxi:6.0:3:*:*:*:*:*:* | ||
| cpe:2.3:o:vmware:esxi:6.0:3a:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



