vmware fusion CVE-2019-5514 is a vulnerability in VMware Fusion
Published on April 1, 2019

VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the host user to execute a JavaScript to perform unauthorized functions on the guest machine where VMware Tools is installed. This may further be exploited to execute commands on the guest machines.

NVD


Products Associated with CVE-2019-5514

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2019-5514 are published in VMware Fusion:

 

Affected Versions

VMware Fusion Version 11.x before 11.0.3 is affected by CVE-2019-5514

Exploit Probability

EPSS
0.50%
Percentile
65.57%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.