CVE-2019-5522 is an out-of-bounds read vulnerability in the vm3dmp driver of VMware Tools for Windows, affecting versions 10.2.x and 10.3.x prior to 10.3.10. A local, non-administrative attacker on a Windows guest machine with VMware Tools installed could exploit this to leak kernel information or cause a denial of service. With a CVSS score of 7.1 (HIGH), the vulnerability has low attack complexity and requires local access, but can lead to high impact on confidentiality and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.3.10CPE matchmatch criteria | cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.