5.8
CVSSv2

CVE-2019-5516

Published: 15/04/2019 Updated: 16/04/2019
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.8 | Impact Score: 5.2 | Exploitability Score: 1.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x prior to 15.0.3 and 14.x prior to 14.1.6), Fusion (11.x prior to 11.0.3 and 10.x prior to 10.1.6) updates address an out-of-bounds vulnerability with the vertex shader functionality. Exploitation of this issue requires an malicious user to have access to a virtual machine with 3D graphics enabled. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. The workaround for this issue involves disabling the 3D-acceleration feature. This feature is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.

Vulnerability Trend

Affected Products

Vendor Product Versions
VmwareEsxi6.5, 6.7

Vendor Advisories

VMware ESXi, Workstation and Fusion updates address an out-of-bounds vulnerability with the vertex shader functionality  Exploitation of this issue requires an attacker to have access to a virtual machine with 3D graphics enabled  Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user pr ...