HomeSecurityVMware Fusion vulnerability allows malicious code execution

VMware Fusion vulnerability allows malicious code execution

VMware has issued a security advisory to address a critical vulnerability in its VMware Fusion product that could allow attackers to execute malicious code.

See also: Cicada3301 ransomware targets VMware ESXi systems

VMware Fusion vulnerability

This vulnerability, identified as CVE-2024-38811, results from the use of an insecure environment variable by the application. With a CVSSv3 score of 8.8, it is classified as important.

VMware Fusion 13.x versions running on macOS are affected . The vulnerability in VMware Fusion allows a malicious actor with standard user rights to execute arbitrary code within the context of the Fusion application. This flaw is particularly concerning as it does not require elevated privileges to exploit, making it accessible to a wider range of potential attackers.

Broadcom has released an update to address this vulnerability, recommending that users upgrade to the stable version specified in VMware's response board, which lists VMware Fusion 13.6 as the updated version.

See also: BlackByte ransomware exploits VMware ESXi vulnerability

There are no known workarounds for this vulnerability, making patching critical to maintaining security. VMware has credited Mykola Grymalyuk of RIPEDA Consulting for responsibly reporting the issue, allowing the company to address the vulnerability before it was actively exploited.

VMware Fusion vulnerability allows malicious code execution

VMware Fusion users are urged to apply the update immediately to mitigate the risk of exploitation of the vulnerability. Given the severity of the vulnerability, organizations should prioritize this update to protect their systems from potential attacks. At this time, there are no known specific exploits for CVE-2024-38811.

How to check the installed version of VMware Fusion

  • Open VMware Fusion on your Mac.
  • Click on “VMware Fusion” in the menu bar at the top of the screen.
  • Select “About VMware Fusion” from the drop-down menu.

A window will appear showing the version number of your VMware Fusion installation.

See also: VMware ESXi flaw used in ransomware attacks

Cyber ​​threats are an ever-increasing risk to individuals and organizations. Cyber ​​vulnerabilities , such as the one in VMware Fusion, refer to weaknesses or security gaps that can be exploited by attackers to compromise information or disrupt services. These vulnerabilities can come from a variety of sources, such as inadequate software updates, poor security settings, or human error. It is critical for organizations and users to understand these vulnerabilities and take proactive steps to protect data and infrastructure from potential attacks.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS