Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CVE-2019-5516

CVE information

Published

4 years ago

Last Modified

4 years ago

CVSSv2.0 Severity

Medium

CVSSv3.1 Severity

Medium

Impact Analysis

Description

VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds vulnerability with the vertex shader functionality. Exploitation of this issue requires an attacker to have access to a virtual machine with 3D graphics enabled. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. The workaround for this issue involves disabling the 3D-acceleration feature. This feature is not enabled by default on ESXi and is enabled by default on Workstation and Fusion..

CVSSv2.0 Score

Severity
Medium
Base Score
5.8/10
Exploit Score
8.6/10
Access Vector
Network
Access Complexity
Medium
Authentication Required
None
Impact Score
4.9/10
Confidentiality Impact
Partial
Availability Impact
Partial
Integrity Impact
None

CVSSv3.1 Score

Severity
Medium
Base Score
6.8/10
Exploit Score
1.6/10
Access Vector
Network
Access Complexity
High
Privileges Required
Low
Impact Score
5.2/10
Confidentiality Impact
High
Availability Impact
High
Integrity Impact
None
Scope
Unchanged
User Interaction
None

Products Affected

CPE Affected Vulnerable Excluding Edit
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*
  Yes
10.0.0 10.1.6
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*
  Yes
14.0.0 14.1.6
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*
  Yes
11.0.0 11.0.3
cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*
  Yes
15.0.0 15.0.3
cpe:2.3:o:vmware:esxi:6.5:-:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707201:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707202:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707203:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707204:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707205:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707206:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707207:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707208:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707209:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707210:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707211:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707212:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707213:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707214:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707215:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707216:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707217:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707218:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707219:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707220:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707221:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707102:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707101:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201707103:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201811001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201811301:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:-:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810201:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810202:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810203:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810204:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810205:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810206:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810207:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810208:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810209:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810210:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810211:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810212:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810213:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810214:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810215:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810216:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810217:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810218:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810219:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810220:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810221:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810222:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810223:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810224:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810225:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810226:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810227:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810228:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810229:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810230:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810231:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810232:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810233:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810234:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810101:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810102:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810103:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201901401:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201901402:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201901403:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904201:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904202:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904203:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904204:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904205:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904206:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904207:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904208:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904209:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904210:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904211:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904212:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904213:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904214:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904215:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904216:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904217:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904218:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904219:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904220:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904221:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904222:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904223:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904224:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904225:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904226:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904227:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904228:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201904229:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201806001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201807001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201808001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201810001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201811001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.7:670-201901001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201701001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201703001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201703002:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201704001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201710001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201712001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201803001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201806001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201808001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201810001:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201810002:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201811002:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:vmware:esxi:6.5:650-201901001:*:*:*:*:*:*
  Yes
- -