CVE-2019-5539

7.8HIGH

Key Information:

Vendor
Vmware
Vendor
CVE Published:
23 December 2019

Summary

VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows machine where Workstation or View Agent is installed.

Affected Version(s)

Horizon View Agent 7.10.x prior to 7.10.1

Horizon View Agent 7.5.x prior 7.5.4

VMware Workstation 15.x prior to 15.5.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.