CVE-2019-5521 is an out-of-bounds read vulnerability in the pixel shader functionality of VMware ESXi, Workstation, and Fusion. This critical vulnerability (CVSS 9.6) allows an attacker with normal user privileges to achieve information disclosure or denial-of-service on the host, provided 3D graphics are enabled on the virtual machine. While not actively exploited (KEV: No), its high FAUCET Risk Score of 91/100 and significant community discussion (11 mentions) indicate potential interest. There are no known public exploits or Metasploit modules available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.1.6CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.0.3CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* | ||
>= 14.0.0, < 14.1.6CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | ||
>= 15.0.0, < 15.0.3CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.5:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.