CVE-2026-41702
EUVD-2026-3051015.05.2026, 07:16
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vmware | fusion | 𝑥 < 26h1 |
𝑥
= Vulnerable software versions