Time-of-check Time-of-use (TOCTOU) Race Condition in Broadcom products - CVE-2019-5519

 

Time-of-check Time-of-use (TOCTOU) Race Condition in Broadcom products - CVE-2019-5519

Published: October 30, 2019


Vulnerability identifier: #VU22409
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5519
CWE-ID:
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to execute arbitrary code on the target system.

The vulnerabity exists due to the Time-of-check Time-of-use (TOCTOU) vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). An attacker with physical access to a virtual machine with a virtual USB controller present can execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.



Affected software

VMware ESXi
VMware Fusion
VMware Workstation
EMC Integrated Data Protection Appliance

How to mitigate CVE-2019-5519

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi600-201903001, ESXi650-201903001, ESXi670-201903001
VMware Fusion - addressed in versions 10.1.6, 11.0.3
VMware Workstation - addressed in versions 14.1.7, 15.0.4
EMC Integrated Data Protection Appliance - update to 2.3.1

External References

Related Security Bulletins