Vulnerability Details CVE-2019-5539
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows machine where Workstation or View Agent is installed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.2%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 4.4
Products affected by CVE-2019-5539
-
cpe:2.3:a:vmware:horizon_view_agent:7.10.0
-
cpe:2.3:a:vmware:horizon_view_agent:7.5.0
-
cpe:2.3:a:vmware:horizon_view_agent:7.5.1
-
cpe:2.3:a:vmware:horizon_view_agent:7.5.2
-
cpe:2.3:a:vmware:horizon_view_agent:7.5.3
-
cpe:2.3:a:vmware:workstation:15.0.0
-
cpe:2.3:a:vmware:workstation:15.0.1
-
cpe:2.3:a:vmware:workstation:15.0.2
-
cpe:2.3:a:vmware:workstation:15.0.3
-
cpe:2.3:a:vmware:workstation:15.0.4
-
cpe:2.3:a:vmware:workstation:15.1.0
-
cpe:2.3:a:vmware:workstation:15.5.0
-
cpe:2.3:o:microsoft:windows:-