CVE-2019-5527: VMware ESXi
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.
Affected products
- VMware ESXi: version 6.0 only; version 6.5 only; version 6.7 only
- VMware Fusion: from 11.0.0, before 11.5.0 (fixed in 11.5.0)
- VMware Horizon: before 5.2.0 (fixed in 5.2.0)
- VMware Remote Console: from 10.0.0, before 10.0.5 (fixed in 10.0.5)
- VMware Workstation: from 15.0.0, before 15.5.0 (fixed in 15.5.0)
Published 2019-10-10. Last modified 2026-06-17.