CVE Vulnerabilities

CVE-2024-38811

Published: Sep 03, 2024 | Modified: Sep 17, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnerability to execute code in the context of the Fusion application.

Affected Software

Name Vendor Start Version End Version
Fusion Vmware 13.0.0 (including) 13.6 (excluding)

References