#VU22408 Buffer overflow in VMware, Inc products - CVE-2019-5518
Published: October 30, 2019
VMware Fusion
VMware Workstation
VMware ESXi
VMware, Inc
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the virtual USB 1.1 UHCI (Universal Host Controller Interface). An attacker with physical access to a virtual machine with a virtual USB controller present can trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.