216.73.216.6

CVE-2026-41702

· Published 15/05/2026 07:16 · Modified 15/05/2026 14:11

Labels: CVE-2026-41702 2026-05-15CVE-2026-41702CWE-367[email protected]

Essential information

Published
15/05/2026 07:16
Modified
15/05/2026 14:11
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
vmware / fusion cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:*

References