VMware Fusion Vulnerability Allows Code Execution with Standard User Privileges
CVE-2024-38811
7.8HIGH
Summary
VMware Fusion versions prior to 13.6 are vulnerable to a code-execution issue stemming from the use of an insecure environment variable. This flaw enables an attacker with standard user privileges to execute arbitrary code within the context of the Fusion application, potentially leading to unauthorized actions or further exploitation of the environment. Organizations using VMware Fusion should address this vulnerability by updating to the latest version to mitigate potential risks associated with this security gap.
Affected Version(s)
Fusion MacOS 13.x < 13.6
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved