CVE-2019-5525: vulnerability in VMware Workstation
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues to execute code on the Linux host where Workstation is installed.
Affected products
VMware · VMware WorkstationRelated CVEs — VMware Workstation
In the same product, most dangerous first.
CVE-2019-5521—CVE-2019-5521EPSS 1.6%CVE-2020-3958—CVE-2020-3958EPSS 0.5%CVE-2019-5539—CVE-2019-5539EPSS 0.4%CVE-2020-3959—CVE-2020-3959EPSS 0.3%CVE-2026-59346CRITICALVMware Workstation and Fusion VMXNET3 integer-overflow vulnerabilityEPSS 0.3%CVE-2026-59347HIGHVMware Workstation and Fusion HGFS stack-based buffer-overflow vulnerabilityEPSS 0.2%