CVE-2024-38811: Code-execution vulnerability
Published Sep 3, 2024
·Updated
VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnerability to execute code in the context of the Fusion application.
Affected Software
1 affected component
vmware Fusion>=13.0.0<13.6
Event History
Sep 3, 2024
CVE Published
via MITRE·09:47 AM
Data Sourced
via MITRE·09:47 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38811?
CVE-2024-38811 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2024-38811?
To fix CVE-2024-38811, you should upgrade to VMware Fusion version 13.6 or later.
3
Who is affected by CVE-2024-38811?
Users of VMware Fusion versions prior to 13.6 are affected by CVE-2024-38811.
4
What can an attacker do with CVE-2024-38811?
An attacker can exploit CVE-2024-38811 to execute arbitrary code within the context of the VMware Fusion application.
5
Is user authentication required to exploit CVE-2024-38811?
No, CVE-2024-38811 can be exploited by an attacker with standard user privileges.