CVE-2019-5515
Summary
| CVE | CVE-2019-5515 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-02 15:29:00 UTC |
| Updated | 2019-05-29 18:29:00 UTC |
| Description | VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) and Fusion (11.x before 11.0.3, 10.x before 10.1.6) updates address an out-of-bounds write vulnerability in the e1000 and e1000e virtual network adapters. Exploitation of this issue may lead to code execution on the host from the guest but it is more likely to result in a denial of service of the guest. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Fusion | All | All | All | All |
| Application | Vmware | Fusion | All | All | All | All |
| Application | Vmware | Workstation | All | All | All | All |
| Application | Vmware | Workstation | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMSA-2019-0005.1 | CONFIRM | www.vmware.com | Vendor Advisory |
| Multiple VMware Products CVE-2019-5515 Out-Of-Bounds Write Local Code Execution Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| ZDI-19-516 | Zero Day Initiative | MISC | www.zerodayinitiative.com | |
| ZDI-19-306 | Zero Day Initiative | MISC | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| VMware Security Advisory 2019-0005 ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.