First published: Mon Dec 23 2019(Updated: )
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows machine where Workstation or View Agent is installed.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Horizon View Agent | >=7.5.0<7.5.4 | |
Vmware Horizon View Agent | >=7.10.0<7.10.1 | |
VMware Workstation | >=15.0.0<15.5.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5539 is a DLL hijacking vulnerability found in VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4).
CVE-2019-5539 has a severity rating of 7.8, which is classified as high.
The affected software for CVE-2019-5539 includes VMware Workstation (version 15.x prior to 15.5.1) and Horizon View Agent (version 7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4).
CVE-2019-5539 allows attackers with normal user privileges to escalate their privileges.
To fix CVE-2019-5539, users should update their VMware Workstation to version 15.5.1 or later, and update their Horizon View Agent to version 7.10.1 or later for 7.10.x, or 7.5.4 or later for 7.5.x.