Vulnerability Details CVE-2019-5540
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory from the host process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 73.9%
CVSS Severity
CVSS v3 Score 7.7
CVSS v2 Score 4.0
Products affected by CVE-2019-5540
-
cpe:2.3:a:vmware:fusion:11.0.0
-
cpe:2.3:a:vmware:fusion:11.0.1
-
cpe:2.3:a:vmware:fusion:11.0.2
-
cpe:2.3:a:vmware:fusion:11.0.3
-
cpe:2.3:a:vmware:fusion:11.1.0
-
cpe:2.3:a:vmware:fusion:11.1.1
-
cpe:2.3:a:vmware:fusion:11.5.0
-
cpe:2.3:a:vmware:workstation:15.0.0
-
cpe:2.3:a:vmware:workstation:15.0.1
-
cpe:2.3:a:vmware:workstation:15.0.2
-
cpe:2.3:a:vmware:workstation:15.0.3
-
cpe:2.3:a:vmware:workstation:15.0.4
-
cpe:2.3:a:vmware:workstation:15.1.0
-
cpe:2.3:a:vmware:workstation:15.5.0
-
cpe:2.3:o:apple:mac_os_x:-