CVE-2019-5519
01.04.2019, 21:30
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain a Time-of-check Time-of-use (TOCTOU) vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this issue requires an attacker to have access to a virtual machine with a virtual USB controller present. This issue may allow a guest to execute code on the host.
Vendor | Product | Version |
---|---|---|
vmware | fusion | 10.0.0 ≤ 𝑥 < 10.1.6 |
vmware | fusion | 11.0.0 ≤ 𝑥 < 11.0.3 |
vmware | workstation | 14.0.0 ≤ 𝑥 < 14.1.7 |
vmware | workstation | 15.0.0 ≤ 𝑥 < 15.0.4 |
vmware | esxi | 6.0 |
vmware | esxi | 6.0:600-201811001 |
vmware | esxi | 6.0:600-201811401 |
vmware | esxi | 6.5 |
vmware | esxi | 6.5:650-201707101 |
vmware | esxi | 6.5:650-201707102 |
vmware | esxi | 6.5:650-201707103 |
vmware | esxi | 6.5:650-201707201 |
vmware | esxi | 6.5:650-201707202 |
vmware | esxi | 6.5:650-201707203 |
vmware | esxi | 6.5:650-201707204 |
vmware | esxi | 6.5:650-201707205 |
vmware | esxi | 6.5:650-201707206 |
vmware | esxi | 6.5:650-201707207 |
vmware | esxi | 6.5:650-201707208 |
vmware | esxi | 6.5:650-201707209 |
vmware | esxi | 6.5:650-201707210 |
vmware | esxi | 6.5:650-201707211 |
vmware | esxi | 6.5:650-201707212 |
vmware | esxi | 6.5:650-201707213 |
vmware | esxi | 6.5:650-201707214 |
vmware | esxi | 6.5:650-201707215 |
vmware | esxi | 6.5:650-201707216 |
vmware | esxi | 6.5:650-201707217 |
vmware | esxi | 6.5:650-201707218 |
vmware | esxi | 6.5:650-201707219 |
vmware | esxi | 6.5:650-201707220 |
vmware | esxi | 6.5:650-201707221 |
vmware | esxi | 6.5:650-201811001 |
vmware | esxi | 6.5:650-201811301 |
vmware | esxi | 6.7 |
vmware | esxi | 6.7:670-201810101 |
vmware | esxi | 6.7:670-201810102 |
vmware | esxi | 6.7:670-201810103 |
vmware | esxi | 6.7:670-201810201 |
vmware | esxi | 6.7:670-201810202 |
vmware | esxi | 6.7:670-201810203 |
vmware | esxi | 6.7:670-201810204 |
vmware | esxi | 6.7:670-201810205 |
vmware | esxi | 6.7:670-201810206 |
vmware | esxi | 6.7:670-201810207 |
vmware | esxi | 6.7:670-201810208 |
vmware | esxi | 6.7:670-201810209 |
vmware | esxi | 6.7:670-201810210 |
vmware | esxi | 6.7:670-201810211 |
vmware | esxi | 6.7:670-201810212 |
vmware | esxi | 6.7:670-201810213 |
vmware | esxi | 6.7:670-201810214 |
vmware | esxi | 6.7:670-201810215 |
vmware | esxi | 6.7:670-201810216 |
vmware | esxi | 6.7:670-201810217 |
vmware | esxi | 6.7:670-201810218 |
vmware | esxi | 6.7:670-201810219 |
vmware | esxi | 6.7:670-201810220 |
vmware | esxi | 6.7:670-201810221 |
vmware | esxi | 6.7:670-201810222 |
vmware | esxi | 6.7:670-201810223 |
vmware | esxi | 6.7:670-201810224 |
vmware | esxi | 6.7:670-201810225 |
vmware | esxi | 6.7:670-201810226 |
vmware | esxi | 6.7:670-201810227 |
vmware | esxi | 6.7:670-201810228 |
vmware | esxi | 6.7:670-201810229 |
vmware | esxi | 6.7:670-201810230 |
vmware | esxi | 6.7:670-201810231 |
vmware | esxi | 6.7:670-201810232 |
vmware | esxi | 6.7:670-201810233 |
vmware | esxi | 6.7:670-201810234 |
vmware | esxi | 6.7:670-201901401 |
vmware | esxi | 6.7:670-201901402 |
vmware | esxi | 6.7:670-201901403 |
𝑥
= Vulnerable software versions
References