CVE-2019-5525: VMware Workstation

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues to execute code on the Linux host where Workstation is installed.

Affected products

  • VMware Workstation: from 15.0.0, before 15.1.0 (fixed in 15.1.0)

Published 2019-06-06. Last modified 2026-06-17.