// For flags

CVE-2019-5518

VMware Workstation UHCI Out-Of-Bounds Access Privilege Escalation Vulnerability

Severity Score

6.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain an out-of-bounds read/write vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this issue requires an attacker to have access to a virtual machine with a virtual USB controller present. This issue may allow a guest to execute code on the host.

VMware ESXi (en las versiones 6.7 anteriores a la ESXi670-201903001, en las 6.5 anteriores a la ESXi650-201903001 y en las 6.0 anteriores a la ESXi600-201903001), Workstation (en las versiones 15.x anteriores a la 15.0.4 y en las 14.x anteriores a la 14.1.7), Fusion (en las versiones 11.x anteriores a la 11.0.3 y en las 10.x anteriores a la 10.1.6) contiene una vulnerabilidad de lectura/escritura fuera de límites en la UHCI virtual (Universal Host Controller Interface) de USB 1.1. La explotación de este fallo requiere que el atacante tenga acceso a una máquina virtual con un controlador USB virtual presente. Este problema puede permitir que un invitado ejecute código en el host

This vulnerability allows local attackers to escalate privileges on vulnerable installations of VMware Workstation. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the processing of data sent to UHCI endpoints. Crafted data sent to UHCI endpoints can trigger a memory access past the end of an allocated data structure. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor.

*Credits: fluoroacetate (@fluoroacetate)
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-01-07 CVE Reserved
  • 2019-03-29 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-125: Out-of-bounds Read
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
>= 10.0.0 < 10.1.6
Search vendor "Vmware" for product "Fusion" and version " >= 10.0.0 < 10.1.6"
-
Affected
Vmware
Search vendor "Vmware"
Fusion
Search vendor "Vmware" for product "Fusion"
>= 11.0.0 < 11.0.3
Search vendor "Vmware" for product "Fusion" and version " >= 11.0.0 < 11.0.3"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
>= 14.0.0 < 14.1.7
Search vendor "Vmware" for product "Workstation" and version " >= 14.0.0 < 14.1.7"
-
Affected
Vmware
Search vendor "Vmware"
Workstation
Search vendor "Vmware" for product "Workstation"
>= 15.0.0 < 15.0.4
Search vendor "Vmware" for product "Workstation" and version " >= 15.0.0 < 15.0.4"
-
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.0
Search vendor "Vmware" for product "Esxi" and version "6.0"
-
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.0
Search vendor "Vmware" for product "Esxi" and version "6.0"
600-201811001
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.0
Search vendor "Vmware" for product "Esxi" and version "6.0"
600-201811401
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
-
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707101
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707102
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707103
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707201
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707202
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707203
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707204
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707205
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707206
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707207
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707208
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707209
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707210
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707211
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707212
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707213
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707214
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707215
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707216
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707217
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707218
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707219
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707220
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201707221
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201811001
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.5
Search vendor "Vmware" for product "Esxi" and version "6.5"
650-201811301
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
-
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810101
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810102
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810103
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810201
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810202
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810203
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810204
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810205
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810206
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810207
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810208
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810209
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810210
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810211
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810212
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810213
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810214
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810215
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810216
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810217
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810218
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810219
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810220
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810221
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810222
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810223
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810224
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810225
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810226
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810227
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810228
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810229
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810230
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810231
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810232
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810233
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201810234
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201901401
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201901402
Affected
Vmware
Search vendor "Vmware"
Esxi
Search vendor "Vmware" for product "Esxi"
6.7
Search vendor "Vmware" for product "Esxi" and version "6.7"
670-201901403
Affected