CVE-2017-7642: Hashicorp Vagrant VMware Fusion
High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.
The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the encoded ruby script or scrub the PATH variable.
Affected products
- Hashicorp Vagrant VMware Fusion: up to and including 4.0.20
Published 2017-08-02. Last modified 2026-06-17.