VMware has issued a security advisory to address a critical vulnerability in its VMware Fusion product that could allow attackers to execute malicious code.
See also: Cicada3301 ransomware targets VMware ESXi systems

This vulnerability, identified as CVE-2024-38811, results from the use of an insecure environment variable by the application. With a CVSSv3 score of 8.8, it is classified as important.
VMware Fusion 13.x versions running on macOS are affected . The vulnerability in VMware Fusion allows a malicious actor with standard user rights to execute arbitrary code within the context of the Fusion application. This flaw is particularly concerning as it does not require elevated privileges to exploit, making it accessible to a wider range of potential attackers.
Broadcom has released an update to address this vulnerability, recommending that users upgrade to the stable version specified in VMware's response board, which lists VMware Fusion 13.6 as the updated version.
See also: BlackByte ransomware exploits VMware ESXi vulnerability
There are no known workarounds for this vulnerability, making patching critical to maintaining security. VMware has credited Mykola Grymalyuk of RIPEDA Consulting for responsibly reporting the issue, allowing the company to address the vulnerability before it was actively exploited.

VMware Fusion users are urged to apply the update immediately to mitigate the risk of exploitation of the vulnerability. Given the severity of the vulnerability, organizations should prioritize this update to protect their systems from potential attacks. At this time, there are no known specific exploits for CVE-2024-38811.
How to check the installed version of VMware Fusion
- Open VMware Fusion on your Mac.
- Click on “VMware Fusion” in the menu bar at the top of the screen.
- Select “About VMware Fusion” from the drop-down menu.
A window will appear showing the version number of your VMware Fusion installation.
See also: VMware ESXi flaw used in ransomware attacks
Cyber threats are an ever-increasing risk to individuals and organizations. Cyber vulnerabilities , such as the one in VMware Fusion, refer to weaknesses or security gaps that can be exploited by attackers to compromise information or disrupt services. These vulnerabilities can come from a variety of sources, such as inadequate software updates, poor security settings, or human error. It is critical for organizations and users to understand these vulnerabilities and take proactive steps to protect data and infrastructure from potential attacks.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
