CVE-2019-5514: VMware Fusion

High severity, CVSS 8.8. EPSS: 3.5% chance of exploitation in the next 30 days.

VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the host user to execute a JavaScript to perform unauthorized functions on the guest machine where VMware Tools is installed. This may further be exploited to execute commands on the guest machines.

Affected products

  • VMware Fusion: from 11.0.0, before 11.0.3 (fixed in 11.0.3)

Published 2019-04-01. Last modified 2026-06-17.