CVE-2019-5517: Medium severity vmware fusion vulnerability
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain multiple out-of-bounds read vulnerabilities in the shader translator. Exploitation of these issues requires an attacker to have access to a virtual machine with 3D graphics enabled. Successful exploitation of these issues may lead to information disclosure or may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. The workaround for these issues involves disabling the 3D-acceleration feature. This feature is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5517?
CVE-2019-5517 has a moderate severity rating as it allows potential exploitation of the vulnerability in VMware products.
How do I fix CVE-2019-5517?
To fix CVE-2019-5517, update affected VMware products to the latest versions as specified in VMware's security advisory.
Which VMware products are affected by CVE-2019-5517?
CVE-2019-5517 affects VMware ESXi versions 6.5 and 6.7, as well as VMware Workstation and Fusion versions prior to their respective updates.
What types of vulnerabilities does CVE-2019-5517 include?
CVE-2019-5517 includes multiple out-of-bounds read vulnerabilities in the shader translator of the affected VMware products.
What can an attacker achieve by exploiting CVE-2019-5517?
An attacker exploiting CVE-2019-5517 may gain unauthorized access to sensitive information or cause denial of service in affected VMware applications.