← Back

CVE-2019-5543

nvd nist
Published: Mar 16, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Windows (15.x before 15.5.2) the folder containing configuration files for the VMware USB arbitration service was found to be writable by all users. A local user on the system where the software is installed may exploit this issue to run commands as any user.

Affected (3)

3 products
Horizon Client
Remote Console
Workstation
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.0.0 to 5.3.0
From 10.0.0 to 11.0.0
From 15.0.0 to 15.5.2
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (2)

Source: security@vmware.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.