CVE-2019-5526 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 9% (pctl 95)
Patch early
A public exploit exists.
Description
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a windows host where Workstation is installed.
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 9.03% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-427 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-05-15 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| vmware | workstation |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | VMware Workstation 15.1.0 - DLL Hijacking | 2019-05-16 |
References
- http://packetstormsecurity.com/files/152946/VMware-Workstation-DLL-Hijacking.html
- http://www.securityfocus.com/bid/108333
- https://www.vmware.com/security/advisories/VMSA-2019-0007.html
- http://packetstormsecurity.com/files/152946/VMware-Workstation-DLL-Hijacking.html
- http://www.securityfocus.com/bid/108333
- https://www.vmware.com/security/advisories/VMSA-2019-0007.html
→ the Explorer · watch your stack · NVD