packetstormsecurity.com
http://packetstormsecurity.com/files/152946/VMware-Workstation-DLL-Hijacking.html CVE-2019-5526
HIGH
VMware workstation Uncontrolled Search Path Element
Record summary
CVE-2019-5526 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a windows host where Workstation is installed.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 22, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
workstationBrowse VMware / workstation | VulnCheck | Version data not supplied | |
VMware Workstation | CVE List | VMware Workstation (15.x before 15.1.0) | affected |
Proofs of concept
1Catalogued exploits
ExploitDBVMware Workstation 15.1.0 - DLL HijackingExploitDB exploitby Miguel Mendez Z. & Claudio Cortes C.Not analyzed1 file
References
4108333vdb entry
http://www.securityfocus.com/bid/108333 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-5526 vmware.com
https://www.vmware.com/security/advisories/VMSA-2019-0007.html