CVE-2019-5539: VMware Horizon View Agent
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows machine where Workstation or View Agent is installed.
Affected products
- VMware Horizon View Agent: from 7.5.0, before 7.5.4 (fixed in 7.5.4); from 7.10.0, before 7.10.1 (fixed in 7.10.1)
- VMware Workstation: from 15.0.0, before 15.5.1 (fixed in 15.5.1)
Published 2019-12-23. Last modified 2026-06-17.