DLL Hijacking Vulnerability in VMware Workstation and Horizon View Agent
CVE-2019-5539
7.8HIGH
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 23 December 2019
Summary
VMware Workstation and Horizon View Agent are susceptible to a DLL hijacking vulnerability triggered by the insecure loading of a dynamic link library (DLL) via Cortado Thinprint. This flaw allows attackers with standard user privileges to gain elevated access rights, potentially escalating their permissions to administrator level on affected Windows machines. Exploitations of this vulnerability pose significant risks to system security and integrity, especially in environments where these products are deployed.
Affected Version(s)
Horizon View Agent 7.10.x prior to 7.10.1
Horizon View Agent 7.5.x prior 7.5.4
VMware Workstation 15.x prior to 15.5.1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved