The company released updates to address vulnerabilities in vCloud Director, ESXi, Workstation and Fusion products. The company also fixed the security flaws disclosed at the Pwn2Own 2019 hacking competition. The critical vulnerabilities are an out-of-bounds read/write vulnerability in the virtual USB 1.1 Universal Host Controller Interface (UHCI) Amat Cama and Richard Zhu of team Fluoroacetate demonstrated two VMware Workstation vulnerabilities, including one that was leveraged in a complex exploit targeting Microsofts Edge browser.”]
Source: https://securityaffairs.co/wordpress/83147/security/vmware-vulnerabilities-pwn2own-2019.html