VYPR

Fusion

by VMware

CVEs (139)

  • CVE-2026-41702HigMay 15, 2026
    risk 0.51cvss 7.8epss 0.00

    VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system…

  • CVE-2023-20871HigApr 25, 2023
    risk 0.51cvss 7.8epss 0.00

    VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system.

  • CVE-2021-22045HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.05

    VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device…

  • CVE-2020-3974HigJul 10, 2020
    risk 0.51cvss 7.8epss 0.00

    VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may…

  • CVE-2020-3969HigJun 24, 2020
    risk 0.51cvss 7.8epss 0.01

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an off-by-one heap-overflow vulnerability in the SVGA device. A malicious actor with…

  • CVE-2020-3948HigMar 16, 2020
    risk 0.51cvss 7.8epss 0.00

    Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privilege escalation vulnerability due to improper file permissions in Cortado Thinprint. Local attackers with non-administrative access to a Linux guest VM with…

  • CVE-2018-6962HigMay 22, 2018
    risk 0.51cvss 7.8epss 0.00

    VMware Fusion (10.x before 10.1.2) contains a signature bypass vulnerability which may lead to a local privilege escalation.

  • CVE-2020-3982HigOct 20, 2020
    risk 0.50cvss 7.7epss 0.01

    VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious…

  • CVE-2019-5542HigNov 20, 2019
    risk 0.50cvss 7.7epss 0.01

    VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM.

  • CVE-2019-5540HigNov 20, 2019
    risk 0.50cvss 7.7epss 0.01

    VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory from the host…

  • CVE-2021-22043HigFeb 16, 2022
    risk 0.49cvss 7.5epss 0.01

    VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.

  • CVE-2020-3967HigJun 25, 2020
    risk 0.49cvss 7.5epss 0.00

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a heap-overflow vulnerability in the USB 2.0 controller (EHCI). A malicious actor…

  • CVE-2020-3966HigJun 25, 2020
    risk 0.49cvss 7.5epss 0.00

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue in the USB 2.0 controller (EHCI). A…

  • CVE-2017-5753MedJan 4, 2018
    risk 0.47cvss 5.6epss 0.93

    Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

  • CVE-2025-41239HigJul 15, 2025
    risk 0.46cvss 7.1epss 0.02

    VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak…

  • CVE-2024-22270HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.01

    VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor…

  • CVE-2024-22269HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.01

    VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.

  • CVE-2024-22268HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.01

    VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service…

  • CVE-2024-22255HigMar 5, 2024
    risk 0.46cvss 7.1epss 0.02

    VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.  

  • CVE-2023-34044HigOct 20, 2023
    risk 0.46cvss 7.1epss 0.00

    VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual…

Page 3 of 7