Description
VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the host user to execute a JavaScript to perform unauthorized functions on the guest machine where VMware Tools is installed. This may further be exploited to execute commands on the guest machines.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-15089 | VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the host user to execute a JavaScript to perform unauthorized functions on the guest machine where VMware Tools is installed. This may further be exploited to execute commands on the guest machines. |
References
History
No history.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-08-04T20:01:52.025Z
Reserved: 2019-01-07T00:00:00.000Z
Link: CVE-2019-5514
No data.
Status : Modified
Published: 2019-04-01T21:30:43.860
Modified: 2024-11-21T04:45:05.207
Link: CVE-2019-5514
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD