← Vulnerability feed

Vulnerability record · CVE-2019-5522 · published 6 June 2019

CVE-2019-5522: Vmware tools out-of-bounds read vulnerability

Vmware · Tools

VMware Tools for Windows update addresses an out of bounds read vulnerability in vm3dmp driver which is installed with vmtools in Windows guest machines. This issue is present in versions 10.2.x and 10.3.x prior to 10.3.10. A local attacker with non-administrative access to a Windows guest with VMware Tools installed may be able to leak kernel information or create a denial of service attack on the same Windows guest machine.

7.1 CVSS 3.0 High EPSS 0.50% · top 59.4% CWE-125 · Out-of-bounds read
7.1CVSS 3.0 base score, v2 3.6
0.50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

VMware Tools for Windows update addresses an out of bounds read vulnerability in vm3dmp driver which is installed with vmtools in Windows guest machines. This issue is present in versions 10.2.x and 10.3.x prior to 10.3.10. A local attacker with non-administrative access to a Windows guest with VMware Tools installed may be able to leak kernel information or create a denial of service attack on the same Windows guest machine.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-5522 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2025-41244VMware Aria Operations and Tools local privilege escalation to rootVMware Aria Operations and VMware Tools contain a local privilege escalation flaw where a non-administrative local actor on a VM with VMware Tools in…KEVEPSS 8.4%analysed3.9CVE-2023-20867VMware Tools authentication bypass from compromised ESXi hostVMware Tools can be forced by a fully compromised ESXi host to fail authentication of host-to-guest operations. This lets a host-level attacker tampe…KEVEPSS 14%analysed7.8CVE-2023-34057Vmware tools improper privilege management vulnerabilityVMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elevate pri…EPSS 0.19%7.8CVE-2022-31676Vmware tools improper privilege management vulnerabilityVMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access …EPSS 0.54%7.8CVE-2021-21999Vmware app volumes uncontrolled search path element vulnerabilityVMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.1…EPSS 1.5%7.8CVE-2016-7079Vmware tools null pointer dereference vulnerabilityThe graphic acceleration functions in VMware Tools 9.x and 10.x before 10.0.9 on OS X allow local users to gain privileges or cause a denial of servi…EPSS 0.37%7.8CVE-2016-7080Vmware tools null pointer dereference vulnerabilityThe graphic acceleration functions in VMware Tools 9.x and 10.x before 10.0.9 on OS X allow local users to gain privileges or cause a denial of servi…EPSS 0.37%7.8CVE-2016-5330Vmware workstation player untrusted search path vulnerabilityUntrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstatio…EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2019-5522), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.