CVE-2017-16873: Hashicorp Vagrant VMware Fusion

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

It is possible to exploit an unsanitized PATH in the suid binary that ships with vagrant-vmware-fusion 4.0.25 through 5.0.4 in order to escalate to root privileges.

Affected products

  • Hashicorp Vagrant VMware Fusion: from 4.0.25, up to and including 5.0.4

Published 2018-03-29. Last modified 2026-06-17.