VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues to execute code on the Linux host where Workstation is installed.
References
Link | Resource |
---|---|
https://www.vmware.com/security/advisories/VMSA-2019-0009.html | Vendor Advisory |
http://www.securityfocus.com/bid/108674 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2019-06-06 12:29
Updated : 2019-06-10 08:46
NVD link : CVE-2019-5525
Mitre link : CVE-2019-5525
JSON object : View
CWE
CWE-416
Use After Free
Products Affected
vmware
- workstation
linux
- linux_kernel