Vmware Fusion vulnerabilities
136 known vulnerabilities affecting vmware/fusion.
Total CVEs
136
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
1
Severity breakdown
CRITICAL10HIGH63MEDIUM58LOW5
Vulnerabilities
Page 2 of 7
CVE-2023-20872HIGHCVSS 8.8v13.0.02023-04-25
CVE-2023-20872 [HIGH] CWE-787 CVE-2023-20872: VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD devic
VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
nvd
CVE-2023-20871HIGHCVSS 7.8≥ 13.0.0, < 13.0.22023-04-25
CVE-2023-20871 [HIGH] CWE-863 CVE-2023-20871: VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write
VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system.
nvd
CVE-2023-20869HIGHCVSS 8.2≥ 13.0.0, < 13.0.22023-04-25
CVE-2023-20869 [HIGH] CWE-787 CVE-2023-20869: VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerabili
VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
nvd
CVE-2023-20870MEDIUMCVSS 6.0≥ 13.0.0, < 13.0.22023-04-25
CVE-2023-20870 [MEDIUM] CWE-125 CVE-2023-20870: VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functio
VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
nvd
CVE-2022-31705HIGHCVSS 8.2≥ 12.0.0, < 12.2.52022-12-14
CVE-2022-31705 [HIGH] CWE-787 CVE-2022-31705: VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbo
nvd
CVE-2021-22043HIGHCVSS 7.5fixed in 4.42022-02-16
CVE-2021-22043 [HIGH] CWE-367 CVE-2021-22043: VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way tempo
VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.
nvd
CVE-2021-22040MEDIUMCVSS 6.7≥ 12.0.0, < 12.2.12022-02-16
CVE-2021-22040 [MEDIUM] CWE-416 CVE-2021-22040: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controll
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
nvd
CVE-2021-22041MEDIUMCVSS 6.7≥ 12.0.0, < 12.2.12022-02-16
CVE-2021-22041 [MEDIUM] CVE-2021-22041: VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
nvd
CVE-2021-22045HIGHCVSS 7.8≥ 12.0.0, < 12.2.02022-01-04
CVE-2021-22045 [HIGH] CWE-787 CVE-2021-22045: VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Works
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this vulnerability in conjunction with o
nvd
CVE-2020-3960HIGHCVSS 8.4≥ 11.0.0, < 11.5.52021-09-15
CVE-2020-3960 [HIGH] CWE-125 CVE-2020-3960: VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x
VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVMe functionality. A malicious actor with local non-administrative access to a virtual machine with a virtual NVMe controller present may be able to read priv
nvd
CVE-2020-3999MEDIUMCVSS 6.5≥ 11.5.0, < 11.5.72020-12-21
CVE-2020-3999 [MEDIUM] CWE-20 CVE-2020-3999: VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior
VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper input validation in GuestInfo. A malicious actor with normal user privilege access to a virtual
nvd
CVE-2020-4004HIGHCVSS 8.2≥ 11.0, < 11.5.72020-11-20
CVE-2020-4004 [HIGH] CWE-416 CVE-2020-4004: VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-2020
VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code
nvd
CVE-2020-3982HIGHCVSS 7.7≥ 11.0, < 11.5.62020-10-20
CVE-2020-3982 [HIGH] CWE-367 CVE-2020-3982: VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a virtual machine may be able to exploit
nvd
CVE-2020-3981MEDIUMCVSS 5.8≥ 11.0, < 11.5.62020-10-20
CVE-2020-3981 [MEDIUM] CWE-125 CVE-2020-3981: VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a virtual machine may be able to exploit
nvd
CVE-2020-3995MEDIUMCVSS 5.3≥ 11.0.0, < 11.1.02020-10-20
CVE-2020-3995 [MEDIUM] CWE-401 CVE-2020-3995: In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x
In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vulnerability. A malicious actor with access to a virtual machine may be able to trigger a memory leak issue resulting in memory resourc
nvd
CVE-2020-3980MEDIUMCVSS 6.7≥ 11.0.0, < 12.0.02020-09-16
CVE-2020-3980 [MEDIUM] CVE-2020-3980: VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configur
VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide path. An attacker with normal user privileges may exploit this issue to trick an admin user into executing malicious code on the system where Fusion is installed.
nvd
CVE-2020-3974HIGHCVSS 7.8≥ 11.0.0, < 11.5.52020-07-10
CVE-2020-3974 [HIGH] CVE-2020-3974: VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) an
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on
nvd
CVE-2020-3967HIGHCVSS 7.5≥ 11.0.0, < 11.5.5v11.x before 11.5.52020-06-25
CVE-2020-3967 [HIGH] CWE-787 CVE-2020-3967: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a heap-overflow vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit this vulnerabilit
cvelistv5nvd
CVE-2020-3968HIGHCVSS 8.2≥ 11.0.0, < 11.5.5v11.x before 11.5.52020-06-25
CVE-2020-3968 [HIGH] CWE-787 CVE-2020-3968: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xHCI). A malicious actor with local administrative privileges on a virtual machine may be able to
cvelistv5nvd
CVE-2020-3966HIGHCVSS 7.5≥ 11.0.0, < 11.5.2v11.x before 11.5.22020-06-25
CVE-2020-3966 [HIGH] CWE-362 CVE-2020-3966: VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESX
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit t
cvelistv5nvd