CVE-2019-5512 is a high-severity privilege escalation vulnerability affecting VMware Workstation (versions 15.x prior to 15.0.3 and 14.x prior to 14.1.6) when running on Windows hosts. The flaw stems from improper handling of COM classes, allowing an attacker to hijack COM classes used by the VMX process. Successful exploitation could lead to complete compromise of the host system. While not actively exploited in the wild, public exploit code exists, and its FAUCET Risk Score of 91/100 indicates significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 14.0.0, < 14.1.6CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | ||
>= 15.0.0, < 15.0.3CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.