CVE-2013-3519: VMware Esx
High severity, CVSS 7.9. EPSS: 0.5% chance of exploitation in the next 30 days.
lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1, when a 32-bit Windows guest OS is used, allows guest OS users to gain guest OS privileges via an application that performs a crafted memory allocation.
Affected products
- VMware Esx: version 4.0 only; version 4.1 only
- VMware ESXi: version 4.0 only; version 4.1 only; version 5.0 only; version 5.1 only
- VMware Fusion: version 5.0 only; version 5.0.1 only; version 5.0.2 only; version 5.0.3 only
- VMware Player: version 5.0 only; version 5.0.1 only; version 5.0.2 only
- VMware Workstation: version 9.0 only; version 9.0.1 only; version 9.0.2 only
Published 2013-12-04. Last modified 2026-06-16.