The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
VMware’s September 3, 2024 security advisory fixed CVE-2024-38811, a code-execution vulnerability in VMware Fusion 13.x before version 13.6. The flaw requires an attacker to have standard local-user access to the Mac, but VMware rated it Important and assigned it a CVSS 3.1 base score of 8.8. Users should install Fusion 13.6 or a later supported release, then check for subsequent security updates.
Update — August 18, 2026: CVE-2024-38811 is a historical 2024 issue, not the newest Fusion vulnerability. Broadcom’s May 14, 2026 advisory covers CVE-2026-41702, a local privilege-escalation flaw rated 7.8. A February 26, 2026 advisory covers additional Fusion and Workstation vulnerabilities rated from 2.7 to 6.1.
The short version
- CVE: CVE-2024-38811
- Advisory: VMware Security Advisory VMSA-2024-0018
- Published: September 3, 2024
- Affected product: VMware Fusion 13.x on macOS, before Fusion 13.6
- Issue: Code execution caused by insecure environment-variable handling
- Attacker requirements: Local access and standard user privileges
- Severity: CVSS v3.1 score of 8.8, rated High by NVD and Important by VMware
- Fix: Fusion 13.6 or a later supported release
- Workaround: None listed by VMware
VMware did not “release a vulnerability.” It released an update addressing one. The original advisory is available from Broadcom’s security advisory portal.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →What CVE-2024-38811 does
CVE-2024-38811 is an insecure-environment-variable vulnerability in VMware Fusion. In practical terms, a malicious actor who already has standard user privileges on the Mac may be able to execute code in the context of the Fusion application.
#1 Best Overall
The available advisory does not describe this as an unauthenticated remote attack against a Fusion server. It also does not explicitly identify the issue as a guest-to-host virtual-machine escape. That distinction matters: this is a vulnerability in the Fusion application and its host security boundary, not simply a flaw in Windows or Linux running inside a virtual machine.
The vulnerability was reported by Mykola Grymalyuk of RIPEDA Consulting. VMware’s advisory confirms responsible disclosure but does not report exploitation in the wild. That should be read as “no exploitation was identified in the vendor advisory,” not as proof that exploitation never occurred anywhere.
Who is affected?
Users running VMware Fusion 13.x before 13.6 on macOS were affected according to VMSA-2024-0018. Fusion 13.6 is the fixed version named in that advisory.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsUsers on Fusion 13.6 or later should not stop checking for updates. Broadcom issued later advisories covering additional Fusion vulnerabilities, so the practical recommendation today is to use the latest supported release available for the Mac rather than deliberately remaining on 13.6.
Users of Fusion 12 or earlier should not assume that the 13.x advisory establishes coverage for those older versions. Check their lifecycle and security-support status separately before deciding whether an upgrade or migration is required.
What does the 8.8 score mean?
The National Vulnerability Database records this CVSS vector:
Rank #2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
| Metric | Meaning |
|---|---|
| AV:L | The attacker needs local access. |
| AC:L | The attack has low complexity once the prerequisites are met. |
| PR:L | Low-level privileges are required. |
| UI:N | No additional victim interaction is required. |
| S:C | The impact can cross a security authority or trust boundary. |
| C:H, I:H, A:H | Successful exploitation could have high confidentiality, integrity, and availability impact. |
That combination explains why a vulnerability requiring local access can still receive a high 8.8 score. CVSS describes technical severity and exploitability characteristics; it is not a percentage chance that a particular user will be attacked.
Free tools Windows power users keep installed
One-click scans. No signup required.
The NVD entry for CVE-2024-38811 labels the score High. VMware’s own advisory uses the severity label Important.
How to update VMware Fusion
- Open VMware Fusion.
- Check the installed version from VMware Fusion > About VMware Fusion.
- If the Mac is running a vulnerable 13.x release, download Fusion 13.6 or a later supported build through the official Broadcom support portal.
- Back up important virtual machines before upgrading. A snapshot can help with rollback, but it is not a substitute for a separate backup.
- Shut down virtual machines if the installer requires it, then install the downloaded DMG.
- Restart Fusion and verify the installed version from the About window.
- Return to Broadcom’s security advisories and check for later Fusion fixes.
Broadcom’s Fusion download and installation guidance says the download is shared between Standard and Professional editions; the license determines the product mode.
If Broadcom will not let you download Fusion
Broadcom’s portal can make remediation more complicated than installing the patch itself:
- No account: Create or sign in to a basic Broadcom Support Portal account.
- “Not Entitled” or unavailable download: Check that the account profile and trade-compliance information are complete. Broadcom says profile screening may be required before downloads become available.
- Older Mac or macOS: Confirm the system requirements and supported host operating systems before upgrading.
- Apple Silicon: The same DMG is used for Intel and Apple Silicon Macs, but the processor architecture still limits guest operating-system compatibility. A universal installer does not let an Apple Silicon Mac run every x86 guest, or an Intel Mac run every ARM guest.
Broadcom’s broader desktop-hypervisor download guidance also discusses newer version naming, including calendar-style labels such as 25H2. Do not assume that a calendar-style release name is automatically equivalent to a particular Fusion 13.x build; verify the version in the relevant advisory and in the installed application.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What if you cannot patch immediately?
Updating is the preferred action because VMware listed no workaround. If a short delay is unavoidable, reduce exposure rather than treating the vulnerable installation as safe:
Rank #3
- Limit local access to trusted users.
- Remove unnecessary accounts and review software with local execution privileges.
- Avoid untrusted Fusion installers, scripts, and virtual-machine files.
- Prioritize Macs used for development, malware analysis, security testing, or sensitive data.
- Keep the system and security software updated while arranging the Fusion upgrade.
These measures do not remove the vulnerability and should not justify a delay of weeks or months.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What this means for Fusion users in 2026
CVE-2024-38811 should not be presented as the latest VMware Fusion security issue. Broadcom’s May 14, 2026 advisory covers CVE-2026-41702, a local privilege-escalation vulnerability rated 7.8. Its February 26, 2026 advisory covers multiple Fusion and Workstation vulnerabilities with scores ranging from 2.7 to 6.1.
Therefore, installing Fusion 13.6 addresses the 2024 flaw, but it is not a complete current-security strategy. Verify that the release you install is still supported and includes later security fixes.
Should you stay with Fusion?
For existing users, updating is usually less disruptive than migrating. Fusion remains a sensible choice when compatibility with existing VMware virtual machines, familiar workflows, snapshots, development tools, and cross-platform VMware knowledge matters.
Broadcom documentation has described Fusion Pro and Workstation Pro as available at no application license cost for personal, educational, and commercial users beginning with the November 11, 2024 announcement. Licensing terms, support eligibility, and portal access are separate issues, so readers should check the current Broadcom licensing guidance for their use case. “Free” should not be interpreted as guaranteed paid support or the absence of account and entitlement requirements.
A switch may make sense if download friction, support arrangements, or Mac integration are more important than VMware compatibility:
- Parallels Desktop is a paid alternative aimed at a polished consumer Windows-on-Mac workflow. Compare current edition and renewal pricing for your geography rather than relying on old prices.
- UTM is a community-oriented option, but graphics, networking, guest-OS, and Apple Silicon support may differ from Fusion for demanding workloads.
- Oracle VirtualBox is a familiar cross-platform option, but it is not a drop-in replacement for every Fusion workflow, especially where Mac integration, Apple Silicon support, 3D acceleration, or VMware VM compatibility matters.
Before migrating, compare Apple Silicon and Windows 11 ARM support, 3D graphics, snapshots and cloning, USB and networking, existing VM compatibility, support options, licensing, and the speed and transparency of security updates.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

