KLA12121
Multiple vulnerabilities in VMware Workstation and Player

Updated: 03/16/2021
Detect date
?
11/12/2019
Severity
?
High
Description

Multiple vulnerabilities were found in VMware Workstation and Player. Malicious users can exploit these vulnerabilities to cause denial of service, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A denial of service vulnerability in the RPC handler can be exploited to cause denial of service.
  2. An information disclosure vulnerability in TSX Asynchronous Abort condition can be exploited locally to obtain sensitive information.
  3. A out-of-bounds write vulnerability in e1000e virtual network adapter can be exploited to cause denial of service.
  4. An information disclosure vulnerability in vmnetdhcp can be exploited to obtain sensitive information.
Affected products

VMware Workstation 15.x earlier than 15.5.1
VMware Player 15.x earlier than 15.5.1

Solution

Update to the latest version
Download VMWare Workstation

Original advisories

VMSA-2019-0020
VMSA-2019-0021

Impacts
?
OSI 
[?]

DoS 
[?]
Related products
VMware Workstation
VMware Player
CVE-IDS
?
CVE-2019-111352.1Warning
CVE-2019-55424.0Warning
CVE-2019-55416.5High
CVE-2019-55404.0Warning
Find out the statistics of the vulnerabilities spreading in your region