VMWare releases Fusion vulnerability with 8.8 rating (cyberscoop.com)
from IllNess@infosec.pub to securitynews@infosec.pub on 04 Sep 2024 18:03
https://infosec.pub/post/17106905

#securitynews

threaded - newest

IllNess@infosec.pub on 04 Sep 2024 18:04 collapse

The security advisory is for version 13.x until 13.6 on the popular virtualization software for macOS. The bug — CVE-2024-38811 — has a CVSSv3 base score of 8.8 and is caused by an insecure environment variable. Mykola Grymalyuk of RIPEDA Consulting reported the vulnerability and VMWare has issued a patched version of the software.

The vulnerability allows a user with standard privileges to execute code within the Fusion application.