CVE-2024-22251: VMware Fusion

Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.

VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure.

Affected products

  • VMware Fusion: from 13.0.0, before 13.5.1 (fixed in 13.5.1)
  • VMware Workstation: from 17.0, before 17.5.1 (fixed in 17.5.1)

Published 2024-02-29. Last modified 2026-06-17.