Command Injection in VMware Fusion - CVE-2019-5514
Published: October 30, 2019
VMware Fusion
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to certain unauthenticated APIs accessible through a web socket. A remote attacker can trick the host user to execute a JavaScript to perform unauthorized functions on the guest machine where VMware Tools is installed and execute arbitrary commands on the target system.