PT-2019-2539 · Linux+1 · Alsa+1
Brice Lhelgouarch
·
Published
2019-06-06
·
Updated
2025-02-09
·
CVE-2019-5525
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VMware Workstation versions 15.x before 15.1.0
Description
The issue is related to a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend of the VMware Workstation hypervisor. This vulnerability can be exploited by a malicious user with normal user privileges on the guest machine, potentially allowing them to execute arbitrary code on the Linux host where Workstation is installed, possibly in conjunction with other issues.
Recommendations
For versions 15.x before 15.1.0, update to version 15.1.0 or later to resolve the issue.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alsa
Vmware Workstation