Out-of-bounds write in VMware Fusion and VMware Workstation - CVE-2019-5515
Published: October 30, 2019
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in the e1000 and e1000e virtual network adapters. A remote authenticated attacker can trigger out-of-bounds write and execute arbitrary code on the host but it is more likely to result in a denial of service of the guest.
Affected software
VMware Workstation
How to mitigate CVE-2019-5515
VMware Workstation - addressed in versions 14.1.6, 15.0.3