CVE-2024-38811: VMware Fusion
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnerability to execute code in the context of the Fusion application.
Affected products
- VMware Fusion: from 13.0.0, before 13.6 (fixed in 13.6)
Published 2024-09-03. Last modified 2026-06-17.