VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnerability to execute code in the context of the Fusion application.
https://www.scmagazine.com/news/vmware-fusion13x-code-execution-bug-patched
https://securityaffairs.com/168009/security/vmware-fusion-cve-2024-38811.html
https://cyberscoop.com/vmware-vulnerability-fushion-cve-2024-38811/