Allele Security Alert
ASA-2019-00318, CVE-2019-5525, VMSA-2019-0009
VMware Workstation 15.x running on Linux
VMware Workstation 15.1.0
Proof of concept
VMware Workstation contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend.
A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues to execute code on the Linux host where Workstation is installed.
Brice L’helgouarc’h (Amossys)
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: June 7, 2019