Rapid7

vulnerability

VMware Workstation: Vulnerability (VMSA-2019-0021) (CVE-2019-5540)

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Nov 21, 2019
Added
Nov 21, 2019
Modified
Mar 30, 2026

Description

VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory from the host process.

Solution

vmware-workstation-upgrade-15_5_1
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.