DLL Hijacking Vulnerability in VMware Workstation and Horizon View Agent
CVE-2019-5539

7.8HIGH

Key Information:

Vendor
Vmware
Vendor
CVE Published:
23 December 2019

Summary

VMware Workstation and Horizon View Agent are susceptible to a DLL hijacking vulnerability triggered by the insecure loading of a dynamic link library (DLL) via Cortado Thinprint. This flaw allows attackers with standard user privileges to gain elevated access rights, potentially escalating their permissions to administrator level on affected Windows machines. Exploitations of this vulnerability pose significant risks to system security and integrity, especially in environments where these products are deployed.

Affected Version(s)

Horizon View Agent 7.10.x prior to 7.10.1

Horizon View Agent 7.5.x prior 7.5.4

VMware Workstation 15.x prior to 15.5.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.