CVE-2017-7642: Hashicorp Vagrant VMware Fusion

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the encoded ruby script or scrub the PATH variable.

Affected products

  • Hashicorp Vagrant VMware Fusion: up to and including 4.0.20

Published 2017-08-02. Last modified 2026-06-17.