#VU18688 Use-after-free in VMware Workstation - CVE-2019-5525
Published: June 6, 2019
VMware Workstation
VMware, Inc
Description
The vulnerability allows a local user to escalate privileges on the host system.
The vulnerability exists due to a use-after-free error in advanced Linux Sound Architecture (ALSA) backend. A local non-privileged user of a guest OS can use a specially crafted application to trigger use-after-free error and execute arbitrary code on the Linux host where Workstation is installed.
Successful exploitation of the vulnerability may allow an attacker to compromise Linux host operating system.