Vulnerabilities

VMware Patches High-Severity Code Execution Flaw in Fusion

VMware rolls out patch for a high-severity code execution vulnerability in the Fusion hypervisor.

VMware

Virtualization software technology vendor VMware on Tuesday pushed out a security update for its Fusion hypervisor to address a high-severity vulnerability that exposes uses to code execution exploits.

The root cause of the issue, tracked as CVE-2024-38811 (CVSS 8.8/10), is an insecure environment variable, VMware notes in an advisory. “VMware Fusion contains a code execution vulnerability due to the usage of an insecure environment variable. VMware has evaluated the severity of this issue to be in the ‘Important’ severity range.”

According to VMware, the CVE-2024-38811 defect could be exploited to execute code in the context of Fusion, which could potentially lead to complete system compromise.

“A malicious actor with standard user privileges may exploit this vulnerability to execute code in the context of the Fusion application,” VMware says.

The company has credited Mykola Grymalyuk of RIPEDA Consulting for identifying and reporting the bug.

The vulnerability impacts VMware Fusion versions 13.x and was addressed in version 13.6 of the application.

Advertisement. Scroll to continue reading.

There are no workarounds available for the vulnerability and users are advised to update their Fusion instances as soon as possible, although VMware makes no mention of the bug being exploited in the wild.

The latest VMware Fusion release also rolls out with an update to OpenSSL version 3.0.14, which was released in June with patches for three vulnerabilities that could lead to denial-of-service conditions or could cause the affected application to become very slow.

Related: Researchers Find 20k Internet-Exposed VMware ESXi Instances

Related: VMware Patches Critical SQL-Injection Flaw in Aria Automation

Related: VMware, Tech Giants Push for Confidential Computing Standards

Related: VMware Patches Vulnerabilities Allowing Code Execution on Hypervisor

Related Content

Vulnerabilities

The patch was announced as Broadcom is attending the Pwn2Own hacking competition in Berlin this week.

Vulnerabilities

The recently patched CVE-2026-22719 can be exploited by an unauthenticated attacker for remote code execution. 

Vulnerabilities

Broadcom has patched several vulnerabilities in VMware Aria Operations, including high-severity flaws.

Vulnerabilities

The critical-severity vulnerability can be exploited via crafted network packets for remote code execution.

Vulnerabilities

Fresh attacks targeted three VMware ESXi vulnerabilities that were disclosed in March 2025 as zero-days.

Vulnerabilities

Broadcom has updated its advisory on CVE-2025-41244 to mention the vulnerability’s in-the-wild exploitation.

Vulnerabilities

Impacting VMware Aria Operations and VMware Tools, the flaw can be exploited to elevate privileges on the VM.

Vulnerabilities

The flaws could allow attackers to escalate privileges, manipulate notifications, and enumerate usernames.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version