CVE-2019-5541 is an out-of-bounds write vulnerability in the e1000e virtual network adapter affecting VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1). This critical vulnerability, rated 9.1 CVSS, allows a highly privileged attacker to achieve code execution on the host from a guest VM or cause a denial-of-service within their own VM. While the attack complexity is low, the scope is changed, meaning a vulnerability in one component can affect resources beyond its security scope. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.0.0, < 15.5.1CPE matchmatch criteria | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.5.1CPE matchmatch criteria | cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.