Vmware Fusion vulnerabilities
136 known vulnerabilities affecting vmware/fusion.
Total CVEs
136
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
1
Severity breakdown
CRITICAL10HIGH63MEDIUM58LOW5
Vulnerabilities
Page 1 of 7
CVE-2026-22715MEDIUMCVSS 5.9≥ 13.0, < 25H2U12026-02-26
CVE-2026-22715 [MEDIUM] CWE-923 CVE-2026-22715: VMWare Workstation and Fusion contain a logic flaw in the management of network packets.
Known att
VMWare Workstation and Fusion contain a logic flaw in the management of network packets.
Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of other Guest VM's.
Resolution: To remediate CVE-2026-22715 please upgrade to VMware Workstation or Fusion Version 2
cvelistv5nvd
CVE-2025-41236CRITICALCVSS 9.3≥ 13.x, ≤ 13.6.42025-07-15
CVE-2025-41236 [CRITICAL] CWE-787 CVE-2025-41236: VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtua
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
cvelistv5nvd
CVE-2025-41238CRITICALCVSS 9.3≥ 13.x, < 13.6.42025-07-15
CVE-2025-41238 [CRITICAL] CWE-787 CVE-2025-41238: VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtua
VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the ex
cvelistv5nvd
CVE-2025-41237CRITICALCVSS 9.3≥ 13.x, < 13.6.42025-07-15
CVE-2025-41237 [CRITICAL] CWE-787 CVE-2025-41237: VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communica
VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitat
cvelistv5nvd
CVE-2025-41239HIGHCVSS 7.1≥ 13.x, < 13.6.42025-07-15
CVE-2025-41239 [HIGH] CWE-908 CVE-2025-41239: VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability
VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets.
cvelistv5nvd
CVE-2025-41227MEDIUMCVSS 5.5≥ 13.x, < 13.6.32025-05-20
CVE-2025-41227 [MEDIUM] CWE-400 CVE-2025-41227: VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service condition.
cvelistv5nvd
CVE-2025-22226MEDIUMCVSS 6.0KEV≥ 13.0.0, < 13.6.32025-03-04
CVE-2025-22226 [HIGH] CWE-125 CVE-2025-22226: VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-o
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
nvd
CVE-2024-38811HIGHCVSS 7.8≥ 13.0.0, < 13.62024-09-03
CVE-2024-38811 [HIGH] CWE-20 CVE-2024-38811: VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an inse
VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges may exploit this vulnerability to execute code in the context of the Fusion application.
nvd
CVE-2024-22273HIGHCVSS 7.8≥ 13.0.0, < 13.5.12024-05-21
CVE-2024-22273 [HIGH] CWE-125 CVE-2024-22273: The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulner
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.
nvd
CVE-2024-22267HIGHCVSS 8.2≥ 13.0.0, < 13.5.22024-05-14
CVE-2024-22267 [CRITICAL] CWE-416 CVE-2024-22267: VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A mal
VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
nvd
CVE-2024-22269MEDIUMCVSS 6.0≥ 13.0.0, < 13.5.22024-05-14
CVE-2024-22269 [HIGH] CWE-200 CVE-2024-22269: VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth devi
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
nvd
CVE-2024-22268MEDIUMCVSS 6.5≥ 13.0.0, < 13.5.22024-05-14
CVE-2024-22268 [HIGH] CWE-787 CVE-2024-22268: VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionali
VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition.
nvd
CVE-2024-22270MEDIUMCVSS 6.0≥ 13.0.0, < 13.5.22024-05-14
CVE-2024-22270 [HIGH] CWE-200 CVE-2024-22270: VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File
VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
nvd
CVE-2024-22255HIGHCVSS 7.1≥ 13.0.0, < 13.5.12024-03-05
CVE-2024-22255 [HIGH] CWE-770 CVE-2024-22255: VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
nvd
CVE-2024-22253MEDIUMCVSS 6.7≥ 13.0.0, < 13.5.12024-03-05
CVE-2024-22253 [CRITICAL] CWE-416 CVE-2024-22253: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controll
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, o
nvd
CVE-2024-22252MEDIUMCVSS 6.7≥ 13.0.0, < 13.5.12024-03-05
CVE-2024-22252 [CRITICAL] CWE-416 CVE-2024-22252: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controll
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, o
nvd
CVE-2024-22251MEDIUMCVSS 4.4≥ 13.0.0, < 13.5.12024-02-29
CVE-2024-22251 [MEDIUM] CWE-125 CVE-2024-22251: VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card
VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure.
nvd
CVE-2023-34046HIGHCVSS 7.0≥ 13.0.0, < 13.5≥ 13.x, < 13.52023-10-20
CVE-2023-34046 [MEDIUM] CWE-367 CVE-2023-34046: VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use)
vulnerability that
VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use)
vulnerability that occurs during installation for the first time (the
user needs to drag or copy the application to a folder from the '.dmg'
volume) or when installing an upgrade. A malicious actor with local non-administrative user privileges may
exploit this vulnerabili
cvelistv5nvd
CVE-2023-34045HIGHCVSS 7.8≥ 13.0.0, < 13.5≥ 13.x, < 13.52023-10-20
CVE-2023-34045 [MEDIUM] CWE-269 CVE-2023-34045: VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs du
VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during
installation for the first time (the user needs to drag or copy the
application to a folder from the '.dmg' volume) or when installing an
upgrade. A malicious actor with local non-administrative user privileges may
exploit this vulnerability to e
cvelistv5nvd
CVE-2023-34044MEDIUMCVSS 6.0≥ 13.0.0, < 13.5≥ 13.x, < 13.52023-10-20
CVE-2023-34044 [HIGH] CWE-125 CVE-2023-34044: VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds
rea
VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds
read vulnerability that exists in the functionality for sharing host
Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual
machine may be able to read privileged information contained in
hypervisor m
cvelistv5nvd
1 / 7Next →