First published: Wed Nov 20 2019(Updated: )
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory from the host process.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Workstation | >=15.0.0<15.5.1 | |
VMware Fusion Pro | >=11.0.0<11.5.1 | |
Apple iOS and macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-5540.
VMware Workstation versions before 15.5.1 and VMware Fusion versions before 11.5.1 are affected.
CVE-2019-5540 has a severity rating of 7.7 (high).
CVE-2019-5540 is an information disclosure vulnerability in vmnetdhcp in VMware Workstation and Fusion.
Successful exploitation of CVE-2019-5540 allows an attacker on a guest VM to leak memory from the host process and disclose sensitive information.