CVE-2019-5518: (Pwn2Own) VMware Workstation UHCI Out-Of-Bounds Access Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on vulnerable installations of VMware Workstation. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of data sent to UHCI endpoints. Crafted data sent to UHCI endpoints can trigger a memory access past the end of an allocated data structure. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor.
Other sources
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain an out-of-bounds read/write vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this issue requires an attacker to have access to a virtual machine with a virtual USB controller present. This issue may allow a guest to execute code on the host.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5518?
The severity of CVE-2019-5518 is classified as high due to its potential for privilege escalation.
How do I fix CVE-2019-5518?
To fix CVE-2019-5518, upgrade to the latest version of VMware Workstation or Fusion as recommended in the security advisory.
What systems are affected by CVE-2019-5518?
CVE-2019-5518 impacts certain versions of VMware Workstation and VMware Fusion, particularly those below specified release versions.
Can CVE-2019-5518 be exploited remotely?
No, CVE-2019-5518 requires local access to execute low-privileged code on the affected system for exploitation.
What is the impact of CVE-2019-5518?
The impact of CVE-2019-5518 is that it allows local attackers to escalate their privileges on affected VMware installations.