logo

VMWare releases Fusion vulnerability with 8.8 rating

ID: 01e51df9-6f53-53d6-84ad-1177a00b4fc5

STIX ID: report--01e51df9-6f53-53d6-84ad-1177a00b4fc5

Feed Name: CyberScoop

Threat Score
65/100

Date Published: 2024-09-03

Date Updated: 2026-04-21

Author: Christian Vasquez

...
...

A critical vulnerability (CVE-2024-38811, CVSSv3 8.8) in VMware Fusion (13.x up to 13.6) allows code execution with standard user privileges due to an insecure environment variable; the flaw was reported by Mykola Grymalyuk and VMware has issued a patched release. The report also highlights that ransomware actors often exploit VMware products and cites the Cicada3301 variant's use of VMware ESXi vulnerabilities, though no active exploitation of this specific Fusion bug is reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.