VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
2024-05-14T16:16:06.610
2025-03-14T15:15:39.803
Modified
CVSSv3.1: 9.3 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | fusion | < 13.5.2 | Yes |
Operating System | apple | macos | - | No |
Application | vmware | workstation | < 17.5.2 | Yes |