ASA-2019-00318 – VMware Workstation: Use-after-free vulnerability


Allele Security Alert

ASA-2019-00318

Identifier(s)

ASA-2019-00318, CVE-2019-5525, VMSA-2019-0009

Title

Use-after-free vulnerability

Vendor(s)

VMware

Product(s)

VMware Workstation

Affected version(s)

VMware Workstation 15.x running on Linux

Fixed version(s)

VMware Workstation 15.1.0

Proof of concept

Unknown

Description

VMware Workstation contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend.

A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues to execute code on the Linux host where Workstation is installed.

Technical details

Unknown

Credits

Brice L’helgouarc’h (Amossys)

Reference(s)

VMSA-2019-0009
https://www.vmware.com/security/advisories/VMSA-2019-0009.html

CVE-2019-5525
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5525

CVE-2019-5525
https://nvd.nist.gov/vuln/detail/CVE-2019-5525

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: June 7, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.