VMware Workstation and Fusion Updates Patch Critical Vulnerability

Summary

VMware has released updates for Workstation and Fusion to address critical vulnerabilities. These flaws could permit attackers with administrative privileges within a virtual machine to execute code on the host system.

IFF Assessment

FOE

The patched vulnerabilities allow attackers to gain unauthorized code execution on the host system, posing a significant risk to defenders.

Severity

7.0 High (AI Estimated)

The CVSS score is estimated considering the potential for local privilege escalation and arbitrary code execution on the host system, impacting the confidentiality, integrity, and availability of the host. The attack vector is local, but the impact is high.

Defender Context

This incident highlights the critical importance of promptly patching virtualization software, as vulnerabilities in these environments can have cascading effects on host systems. Defenders should prioritize updating VMware Workstation and Fusion and maintain vigilance for other vulnerabilities within virtualization platforms.

Read Full Story →