Lucene search

K
cveVmwareCVE-2019-5515
HistoryApr 02, 2019 - 3:29 p.m.

CVE-2019-5515

2019-04-0215:29:00
CWE-787
vmware
web.nvd.nist.gov
49
vmware
workstation
fusion
updates
e1000
e1000e
vulnerability
code execution
denial of service
nvd

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.007

Percentile

80.2%

VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) and Fusion (11.x before 11.0.3, 10.x before 10.1.6) updates address an out-of-bounds write vulnerability in the e1000 and e1000e virtual network adapters. Exploitation of this issue may lead to code execution on the host from the guest but it is more likely to result in a denial of service of the guest.

Affected configurations

Nvd
Node
vmwarefusionRange10.0.010.1.6
OR
vmwarefusionRange11.0.011.0.3
OR
vmwareworkstationRange14.0.014.1.6
OR
vmwareworkstationRange15.0.015.0.3
VendorProductVersionCPE
vmwarefusion*cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*
vmwareworkstation*cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "VMware Workstation and Fusion",
    "vendor": "VMware",
    "versions": [
      {
        "status": "affected",
        "version": "Workstation 15.x before 15.0.3"
      },
      {
        "status": "affected",
        "version": "Workstation 14.x before 14.1.6"
      },
      {
        "status": "affected",
        "version": "Fusion 11.x before 11.0.3"
      },
      {
        "status": "affected",
        "version": "Fusion 10.x before 10.1.6"
      }
    ]
  }
]

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.007

Percentile

80.2%