Vulnerability Database

309,961

Total vulnerabilities in the database

CVE-2024-38811

VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnerability to execute code in the context of the Fusion application.

  • Published: Sep 3, 2024
  • Updated: Nov 16, 2025
  • CVE: CVE-2024-38811
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.8
  • AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CWEs: