CVE-2017-16001: Hashicorp Vagrant
High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
Affected products
- Hashicorp Vagrant: version 5.0.1 only
Published 2017-11-06. Last modified 2026-06-17.