CyberzSOC

Publication detail
← Back to advisories & guidance

2024-091: High Severity Vulnerability in VMware Fusion for MacOS ↗ source

September 4, 2024 CERT-EU Advisory

Summary

which could allow attackers to execute arbitrary code on macOS systems [1]. ThevulnerabilityCVE-2024-38811,withaCVSSscoreof8.8,arisesfromimproperhandlingof environment variables, allowing malicious actors with standard user privileges to execute arbitrary code within the VMware Fusion environment. This may lead to full-system compromise, potentially exposing sensitive data and disrupting operations. CERT-EU recommends to immediately update VMware Fusion to a fixed version.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-38811 8.8 High n/a Fusion VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.