CVE-2019-5520: VMware ESXi

Medium severity, CVSS 5.9. EPSS: 1% chance of exploitation in the next 30 days.

VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds read vulnerability. Exploitation of this issue requires an attacker to have access to a virtual machine with 3D graphics enabled. Successful exploitation of this issue may lead to information disclosure.The workaround for this issue involves disabling the 3D-acceleration feature. This feature is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.

Affected products

  • VMware ESXi: version 6.5 only; version 6.7 only
  • VMware Fusion: from 10.0.0, before 10.1.6 (fixed in 10.1.6); from 11.0.0, before 11.0.3 (fixed in 11.0.3)
  • VMware Workstation: from 14.0.0, before 14.1.6 (fixed in 14.1.6); from 15.0.0, before 15.0.3 (fixed in 15.0.3)

Published 2019-04-15. Last modified 2026-06-17.