VMware Patches Severe Security Flaws in Workstation and Fusion Products
ID: 3474d2c8-6af5-5bd1-aacb-74277eb40217
STIX ID: report--3474d2c8-6af5-5bd1-aacb-74277eb40217
Feed Name: The Hacker News
VMware disclosed four vulnerabilities affecting Workstation 17.x and Fusion 13.x — notably CVE-2024-22267 (Bluetooth use-after-free, CVSS 9.3) which can allow code execution as the VMX process on the host, plus a Shader heap overflow (DoS) and two information disclosure bugs in Bluetooth and HGFS. Patches are available in Workstation 17.5.2 and Fusion 13.5.2; temporary mitigations include disabling Bluetooth support and 3D acceleration, and several of the bugs were demonstrated at Pwn2Own.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
