peter bassill · operator
$ cve CVE-2019-5526 JSON

CVE-2019-5526 EXPLOIT

7.8
HIGH · CVSS 3.0 · EPSS 9% (pctl 95)

Patch early

A public exploit exists.

Description

VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a windows host where Workstation is installed.

Scoring

CVSS7.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS9.03% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-427
On CISA KEVno
Public exploityes
Published2019-05-15
Last modified2026-06-17

Affected (1)

VendorProduct
vmwareworkstation

Public exploits

SourceTitleDate
exploit-dbVMware Workstation 15.1.0 - DLL Hijacking2019-05-16

References

→ the Explorer  ·  watch your stack  ·  NVD