VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a windows host where Workstation is installed.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://www.vmware.com/security/advisories/VMSA-2019-0007.html | vendor advisory |
http://www.securityfocus.com/bid/108333 | third party advisory vdb entry |
http://packetstormsecurity.com/files/152946/VMware-Workstation-DLL-Hijacking.html | third party advisory |