CVE-2026-41702: TOCTOU local privilege escalation vulnerability
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41702?
CVE-2026-41702 is a high-severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2026-41702?
To fix CVE-2026-41702, it is recommended to update VMware Fusion to the latest patched version.
Who is affected by CVE-2026-41702?
CVE-2026-41702 affects users of VMware Fusion who have non-administrative local user privileges.
What type of vulnerability is CVE-2026-41702?
CVE-2026-41702 is a Time-of-check Time-of-use (TOCTOU) vulnerability that can lead to local privilege escalation.
Can an attacker exploit CVE-2026-41702 remotely?
No, CVE-2026-41702 can only be exploited by a malicious actor with local access to the affected system.