Site icon TheCyberThrone

VMware fixes CVE-2024-38811 in Fusion

Advertisements

VMware has released patch for a high-severity flaw that has been identified in VMware Fusion, that  allow a malicious actor with standard user privileges to execute arbitrary code within the context of the Fusion application.

The vulnerability tracked as CVE-2024-38811 with a CVSS score of 8.8, stems from the use of an insecure environment variable within VMware Fusion, a tool widely used by MacOS users to run virtual machines. This weakness could allow a malicious actor with standard user privileges to execute arbitrary code within the context of the Fusion application. Such an exploit could potentially lead to unauthorized access, data breaches, or further system compromise, depending on the nature of the code executed.

Advertisements

The vulnerability affects VMware Fusion version 13.x running on the MacOS platform. Users running these versions are at risk and should take immediate action to protect their systems.

VMware has released a new patched version of the software, VMware Fusion 13.6. Users are strongly advised to update their installations to this version to mitigate the risk posed by CVE-2024-38811.

Exit mobile version