ASA-2019-00167 – VMware: Unauthenticated APIs Security vulnerability


Allele Security Alert

ASA-2019-00167

Identifier(s)

ASA-2019-00167, CVE-2019-5514, VMSA-2019-0005

Title

Unauthenticated APIs Security vulnerability

Vendor(s)

VMware

Product(s)

VMware Fusion Pro / Fusion (Fusion)

Affected version(s)

VMware Fusion Pro / Fusion (Fusion) running on OSX version 11.x

Fixed version(s)

VMware Fusion Pro / Fusion (Fusion) running on OSX version 11.0.3

Proof of concept

Unknown

Description

VMware Fusion contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the host user to execute a JavaScript to perform unauthorized functions on the guest machine where VMware Tools is installed. This may further be exploited to execute commands on the guest machines.

Technical details

Unknown

Credits

CodeColorist and Csaba Fitzl

Reference(s)

[Security-announce] New VMSA-2019-0005 – VMware ESXi, Workstation and Fusion updates address multiple security issues
https://lists.vmware.com/pipermail/security-announce/2019/000454.html

VMSA-2019-0005
https://www.vmware.com/security/advisories/VMSA-2019-0005.html

CVE-2019-5514
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5514

CVE-2019-5514
https://nvd.nist.gov/vuln/detail/CVE-2019-5514

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: April 2, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.