Vmware Fusion vulnerabilities
137 known vulnerabilities affecting vmware/fusion.
Total CVEs
137
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
6
Severity breakdown
CRITICAL10HIGH64MEDIUM58LOW5
Vulnerabilities
Page 5 of 7
CVE-2020-3957P4HIGHCVSS 7.0≥ 11.0.0, < 11.5.52020-05-29
CVE-2020-3957 [HIGH] CWE-367 CVE-2020-3957: VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizo
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate
nvd
CVE-2023-34046P4HIGHCVSS 7.0≥ 13.0.0, < 13.5≥ 13.x, < 13.52023-10-20
CVE-2023-34046 [HIGH] CWE-367 CVE-2023-34046: VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that
VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use)
vulnerability that occurs during installation for the first time (the
user needs to drag or copy the application to a folder from the '.dmg'
volume) or when installing an upgrade. A malicious actor with local non-administrative user privileges may
exploit this vulnerability
nvd
CVE-2013-3519P4HIGHCVSS 7.9v5.0v5.0.1+2 more2013-12-04
CVE-2013-3519 [HIGH] CWE-264 CVE-2013-3519: lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5
lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1, when a 32-bit Windows guest OS is used, allows guest OS users to gain guest OS privileges via an application that performs a crafted memory allocation.
nvd
CVE-2009-1244P4MEDIUMCVSS 6.8≤ 2.0.3v1.0+7 more2009-04-13
CVE-2009-1244 [MEDIUM] CVE-2009-1244: Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and ea
Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745; VMware Fusion before 2.0.4 build 159196; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS u
nvd
CVE-2021-22040P4MEDIUMCVSS 6.7≥ 12.0.0, < 12.2.12022-02-16
CVE-2021-22040 [MEDIUM] CWE-416 CVE-2021-22040: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controll
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
nvd
CVE-2019-5520P4MEDIUMCVSS 5.9≥ 10.0.0, < 10.1.6≥ 11.0.0, < 11.0.3+2 more2019-04-15
CVE-2019-5520 [MEDIUM] CWE-125 CVE-2019-5520: VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x be
VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds read vulnerability. Exploitation of this issue requires an attacker to have access to a virtual machine with 3D graphics enabled. Su
nvd
CVE-2026-22715P4MEDIUMCVSS 5.9≥ 13.0, < 25H2U12026-02-26
CVE-2026-22715 [MEDIUM] CWE-923 CVE-2026-22715: VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known att
VMWare Workstation and Fusion contain a logic flaw in the management of network packets.
Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of other Guest VM's.
Resolution: To remediate CVE-2026-22715 please upgrade to VMware Workstation or Fusion Version 25H
nvd
CVE-2021-22041P4MEDIUMCVSS 6.7≥ 12.0.0, < 12.2.12022-02-16
CVE-2021-22041 [MEDIUM] CVE-2021-22041: VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
nvd
CVE-2015-2336P4MEDIUMCVSS 5.8v6.0v6.0.1+6 more2015-06-13
CVE-2015-2336 [MEDIUM] CVE-2015-2336: TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before
TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to execute arbitrary code on the host OS via unspecified vectors, a diffe
nvd
CVE-2015-2337P4MEDIUMCVSS 5.8v6.0v6.0.1+6 more2015-06-13
CVE-2015-2337 [MEDIUM] CWE-399 CVE-2015-2337: TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before
TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to execute arbitrary code on the host OS via unspecified vectors.
nvd
CVE-2010-4296P4HIGHCVSS 7.2v3.1v3.1.1+1 more2010-12-06
CVE-2010-4296 [HIGH] CWE-863 CVE-2010-4296: vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x befor
vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not properly load libraries, which allows host OS users to gain privileges via vectors involving shared object files.
nvd
CVE-2010-1139P4HIGHCVSS 7.2v2.0v2.0.1+5 more2010-04-12
CVE-2010-1139 [HIGH] CWE-134 CVE-2010-1139: Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4
Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Linux, and VMware Fusion 2.x before 2.0.7 build 246742, allows local users to gain privileges via format string specifiers in process metadata.
nvd
CVE-2019-5519P4MEDIUMCVSS 6.8≥ 10.0.0, < 10.1.6≥ 11.0.0, < 11.0.32019-04-01
CVE-2019-5519 [MEDIUM] CWE-367 CVE-2019-5519: VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-20190300
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain a Time-of-check Time-of-use (TOCTOU) vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this
nvd
CVE-2017-4950P4HIGHCVSS 7.0≥ 8.0, < 8.5.10≥ 10.0, < 10.1.1+2 more2018-01-11
CVE-2017-4950 [HIGH] CWE-190 CVE-2017-4950: VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when I
VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an out-of-bound read which can then be used to execute code on the host in conjunction with other issues. Note: IPv6 mode for VMNAT is not enabled by default.
nvd
CVE-2017-4949P4HIGHCVSS 7.0≥ 8.0, < 8.5.10≥ 10.0, < 10.1.1+2 more2018-01-11
CVE-2017-4949 [HIGH] CWE-416 CVE-2017-4949: VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6
VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may allow a guest to execute code on the host. Note: IPv6 mode for VMNAT is not enabled by default.
nvd
CVE-2019-5518P4MEDIUMCVSS 6.8≥ 10.0.0, < 10.1.6≥ 11.0.0, < 11.0.32019-04-01
CVE-2019-5518 [MEDIUM] CWE-125 CVE-2019-5518: VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-20190300
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before 14.1.7), Fusion (11.x before 11.0.3, 10.x before 10.1.6) contain an out-of-bounds read/write vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of this issue req
nvd
CVE-2009-3282P4HIGHCVSS 7.8≤ 2.0.5v1.0+9 more2009-10-16
CVE-2009-3282 [HIGH] CWE-189 CVE-2009-3282: Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows hos
Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows host OS users to cause a denial of service to the host OS via unspecified vectors.
nvd
CVE-2020-3981P4MEDIUMCVSS 5.8≥ 11.0, < 11.5.62020-10-20
CVE-2020-3981 [MEDIUM] CWE-125 CVE-2020-3981: VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a virtual machine may be able to exploit
nvd
CVE-2020-3980P4MEDIUMCVSS 6.7≥ 11.0.0, < 12.0.02020-09-16
CVE-2020-3980 [MEDIUM] CVE-2020-3980: VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configur
VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide path. An attacker with normal user privileges may exploit this issue to trick an admin user into executing malicious code on the system where Fusion is installed.
nvd
CVE-2008-2098P4MEDIUMCVSS 6.9v1.1v1.1.12008-06-02
CVE-2008-2098 [MEDIUM] CWE-119 CVE-2008-2098: Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 befor
Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, VMware ACE 2 before 2.0.2 build 93057, and VMware Fusion before 1.1.2 build 87978, when folder sharing is used, allows guest OS users to execute arbitrary code on the host OS via unspecified
nvd