Out of Bounds Read Vulnerability in VMware Tools for Windows
CVE-2019-5522

7.1HIGH

Key Information:

Vendor
Vmware
Vendor
CVE Published:
6 June 2019

Summary

VMware Tools for Windows contains an out of bounds read vulnerability in the vm3dmp driver, affecting Windows guest machines where VMware Tools is installed. This vulnerability is found in versions 10.2.x and 10.3.x prior to 10.3.10. A local attacker with non-administrative access could potentially exploit this flaw to expose sensitive kernel information or disrupt service on the affected Windows guest machine.

Affected Version(s)

VMware Tools for Windows VMware Tools for Windows (10.x before 10.3.10)

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.