CVE-2019-5539
7.8HIGH
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 23 December 2019
Summary
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows machine where Workstation or View Agent is installed.
Affected Version(s)
Horizon View Agent 7.10.x prior to 7.10.1
Horizon View Agent 7.5.x prior 7.5.4
VMware Workstation 15.x prior to 15.5.1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved