ASA-2019-00317 – VMware: VMware Tools out of bounds read vulnerability


Allele Security Alert

ASA-2019-00317

Identifier(s)

ASA-2019-00317, CVE-2019-5522, VMSA-2019-0009

Title

VMware Tools out of bounds read vulnerability

Vendor(s)

VMware

Product(s)

VMware Tools

Affected version(s)

VMware Tools for Windows 10.x running on Windows

Fixed version(s)

VMware Tools for Windows 10.3.10

Proof of concept

Unknown

Description

VMware Tools update addresses an out of bounds read vulnerability in vm3dmp driver which is installed with vmtools in Windows guest machines.

A local attacker with non-administrative access to a Windows guest with VMware Tools installed may be able to leak kernel information or create a denial of service attack on the same Windows guest machine.

Technical details

Unknown

Credits

ChenNan (Tencent ZhanluLab) and RanchoIce (Tencent ZhanluLab)

Reference(s)

VMSA-2019-0009
https://www.vmware.com/security/advisories/VMSA-2019-0009.html

CVE-2019-5522
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5522

CVE-2019-5522
https://nvd.nist.gov/vuln/detail/CVE-2019-5522

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: June 7, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.