CVE-2019-5536

MEDIUM

VMware ESXi <6.7-ESXi670-201908101-SG & <6.5-ESXi650-201910401-SG, ...

Title source: llm
STIX 2.1

Description

VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. Exploitation of this issue require an attacker to have access to a virtual machine with 3D graphics enabled. It is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0066
EPSS Percentile 71.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (2)
vmware/esxi 6.5 (45 CPE variants)
vmware/esxi 6.7 (5 CPE variants)
Published Oct 28, 2019
Tracked Since Feb 18, 2026