CVE-2013-3519

Description

lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1, when a 32-bit Windows guest OS is used, allows guest OS users to gain guest OS privileges via an application that performs a crafted memory allocation.

Risk Information

Base Score
8.4
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.17

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2013-3519,CVE-2014-1208 are affected in VMware Fusion for MAC 5.0Mac
Vulnerabilities CVE-2013-3519 are affected in VMware Fusion for MAC 5.0.1Mac
Vulnerabilities CVE-2013-3519 are affected in VMware Fusion for MAC 5.0.2Mac
Vulnerabilities CVE-2013-3519 are affected in VMware Fusion for MAC 5.0.3Mac
Vulnerabilities CVE-2013-1406,CVE-2013-3519,CVE-2014-1208 are affected in VMware Fusion for MAC 5.0Mac
Vulnerabilities CVE-2013-1406,CVE-2013-3519 are affected in VMware Fusion for MAC 5.0.1Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)
PATCH-605160VMware Fusion for MAC 13.0.2 (Deployment-Only)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234