VMware VMware Fusion (11.x prior to 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the host user to execute a JavaScript to perform unauthorized functions on the guest machine where VMware Tools is installed. This may further be exploited to execute commands on the guest machines.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
vmware fusion |