CVE-2019-5526
Status: ModifiedHigh (7.8)—💥 Exploit
VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a windows host where Workstation is installed.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 9.03%
- Percentile among all scored CVEs: 95
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · VMware Workstation 15.1.0 - DLL Hijacking (5/16/2019)
Affected technologies (1)
CWEs
- CWE-427
References
- http://packetstormsecurity.com/files/152946/VMware-Workstation-DLL-Hijacking.html
- http://www.securityfocus.com/bid/108333
- https://www.vmware.com/security/advisories/VMSA-2019-0007.html
- http://packetstormsecurity.com/files/152946/VMware-Workstation-DLL-Hijacking.html
- http://www.securityfocus.com/bid/108333
- https://www.vmware.com/security/advisories/VMSA-2019-0007.html
Raw JSON (NVD)
Show
{
"id": "CVE-2019-5526",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "security@vmware.com",
"affectedData": [
{
"vendor": "n/a",
"product": "VMware Workstation",
"versions": [
{
"status": "affected",
"version": "VMware Workstation (15.x before 15.1.0)"
}
]
}
]
}
],
"published": "2019-05-15T16:29:00.910",
"references": [
{
"url": "http://packetstormsecurity.com/files/152946/VMware-Workstation-DLL-Hijacking.html",
"tags": [
"Third Party Advisory"
],
"source": "security@vmware.com"
},
{
"url": "http://www.securityfocus.com/bid/108333",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "security@vmware.com"
},
{
"url": "https://www.vmware.com/security/advisories/VMSA-2019-0007.html",
"tags": [
"Vendor Advisory"
],
"source": "security@vmware.com"
},
{
"url": "http://packetstormsecurity.com/files/152946/VMware-Workstation-DLL-Hijacking.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/108333",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.vmware.com/security/advisories/VMSA-2019-0007.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-427"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a windows host where Workstation is installed."
},
{
"lang": "es",
"value": "VMware Workstation (versión 15.x anterior de 15.1.0) contiene un problema de secuestro de DLL porque la aplicación carga inapropiadamente algunos archivos DLL. La explotación con éxito de este problema puede permitir a los atacantes con privilegios de usuario normales escalar sus privilegios al administrador en un host de Windows donde está instalada la Estación de trabajo."
}
],
"lastModified": "2026-06-17T02:37:50.957",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E2A748C-18BC-4EA0-B599-CFAE4E36B00B",
"versionEndExcluding": "15.1.0",
"versionStartIncluding": "15.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@vmware.com"
}