#VU19921 Out-of-bounds write


Published: 2019-08-02

Vulnerability identifier: #VU19921

Vulnerability risk: Medium

CVSSv3.1: 6.2 [CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-5684

CWE-ID: CWE-125

Exploitation vector: Local network

Exploit availability: No

Vulnerable software:
VMware Fusion
Client/Desktop applications / Virtualization software
VMware Workstation
Client/Desktop applications / Virtualization software
VMware ESXi
Operating systems & Components / Operating system

Vendor: VMware, Inc

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input. A remote unprivileged user with access to a guest operating system can trigger out-of-bounds write and execute arbitrary code on the target system.

Note, the vulnerability can be exploited only if the host has an affected NVIDIA graphics driver.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

VMware Fusion: 10.1.0 - 11.0.2

VMware Workstation: 14.1.1 - 15.0.2

VMware ESXi: 6.0 - 6.7


External links
http://www.vmware.com/security/advisories/VMSA-2019-0012.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability