Allele Security Alert
ASA-2019-00167
Identifier(s)
ASA-2019-00167, CVE-2019-5514, VMSA-2019-0005
Title
Unauthenticated APIs Security vulnerability
Vendor(s)
VMware
Product(s)
VMware Fusion Pro / Fusion (Fusion)
Affected version(s)
VMware Fusion Pro / Fusion (Fusion) running on OSX version 11.x
Fixed version(s)
VMware Fusion Pro / Fusion (Fusion) running on OSX version 11.0.3
Proof of concept
Unknown
Description
VMware Fusion contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the host user to execute a JavaScript to perform unauthorized functions on the guest machine where VMware Tools is installed. This may further be exploited to execute commands on the guest machines.
Technical details
Unknown
Credits
CodeColorist and Csaba Fitzl
Reference(s)
[Security-announce] New VMSA-2019-0005 – VMware ESXi, Workstation and Fusion updates address multiple security issues
https://lists.vmware.com/pipermail/security-announce/2019/000454.html
VMSA-2019-0005
https://www.vmware.com/security/advisories/VMSA-2019-0005.html
CVE-2019-5514
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5514
CVE-2019-5514
https://nvd.nist.gov/vuln/detail/CVE-2019-5514
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: April 2, 2019