RULE(RULE ID:321736)

Rule General Information
Release Date: 2019-04-22
Rule Name: VMware Fusion Guest VM Remote Code Execution Vulnerability (CVE-2019-5514)
Severity:
CVE ID:
CNNVD ID:
Rule Protection Details
Description: VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the host user to execute a JavaScript to perform unauthorized functions on the guest machine where VMware Tools is installed. This may further be exploited to execute commands on the guest machines.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:107637
http://packetstormsecurity.com/files/152290/VMware-Security-Advisory-2019-0005.html
https://www.vmware.com/security/advisories/VMSA-2019-0005.html
Solutions
The vendor has updated advisory in its official website. Please visit:
https://www.vmware.com/