QID 376422

Date Published: 2022-02-17

QID 376422: VMware Workstation and VMware Fusion Multiple Vulnerabilities (VMSA-2022-0004)

VMware Workstation, Fusion is a hosted hypervisor that runs on x64 versions of Windows and Linux operating systems.

Affected Versions:
VMware Workstation Pro 16.x prior to 16.2.1
VMware Workstation Player 16.x prior to 16.2.1
VMware Fusion prior to 12.x prior to 12.2.1

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Workstation and Fusion .exe file.

A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6 severity.
  • Solution
    Vmware has released patch for VMware Workstation and VMware Fusion.

    Refer to VMware advisory VMSA-2022-0004 for more information.

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0004 URL Logo www.vmware.com/security/advisories/VMSA-2022-0004.html