PT-2019-2539 · Linux+1 · Alsa+1

Brice Lhelgouarch

·

Published

2019-06-06

·

Updated

2025-02-09

·

CVE-2019-5525

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware Workstation versions 15.x before 15.1.0
Description The issue is related to a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend of the VMware Workstation hypervisor. This vulnerability can be exploited by a malicious user with normal user privileges on the guest machine, potentially allowing them to execute arbitrary code on the Linux host where Workstation is installed, possibly in conjunction with other issues.
Recommendations For versions 15.x before 15.1.0, update to version 15.1.0 or later to resolve the issue.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2019-02384
CVE-2019-5525

Affected Products

Alsa
Vmware Workstation