First published: Tue Sep 03 2024(Updated: )
VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnerability to execute code in the context of the Fusion application.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Fusion Pro | >=13.0.0<13.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38811 has been rated as a medium severity vulnerability.
To fix CVE-2024-38811, you should upgrade to VMware Fusion version 13.6 or later.
Users of VMware Fusion versions prior to 13.6 are affected by CVE-2024-38811.
An attacker can exploit CVE-2024-38811 to execute arbitrary code within the context of the VMware Fusion application.
No, CVE-2024-38811 can be exploited by an attacker with standard user privileges.