CVE-2024-38811

high

Description

VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnerability to execute code in the context of the Fusion application.

References

https://www.scmagazine.com/news/vmware-fusion13x-code-execution-bug-patched

https://securityaffairs.com/168009/security/vmware-fusion-cve-2024-38811.html

https://cyberscoop.com/vmware-vulnerability-fushion-cve-2024-38811/

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24939

Details

Source: Mitre, NVD

Published: 2024-09-03

Updated: 2024-09-17

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High