CVE-2019-5527 is a use-after-free vulnerability in the virtual sound device affecting VMware ESXi, Workstation, Fusion, VMRC, and Horizon Client. This vulnerability carries a high CVSSv3 base score of 8.8, indicating a local attack vector with low complexity that can lead to high confidentiality, integrity, and availability impacts. While it has a high FAUCET Risk Score of 67/100, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.0CPE matchmatch criteria | cpe:2.3:a:vmware:horizon:*:*:*:*:*:linux:*:* | ||
< 5.2.0CPE matchmatch criteria | cpe:2.3:a:vmware:horizon:*:*:*:*:*:macos:*:* | ||
< 5.2.0CPE matchmatch criteria | cpe:2.3:a:vmware:horizon:*:*:*:*:*:windows:*:* | ||
>= 10.0.0, < 10.0.5CPE matchmatch criteria | cpe:2.3:a:vmware:remote_console:*:*:*:*:*:linux:*:* | ||
>= 10.0.0, < 10.0.5CPE matchmatch criteria | cpe:2.3:a:vmware:remote_console:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.