VMware discloses flaws in Workstation and Fusion Pro products after making them free for personal use
VMware has warned customers of a series of high severity flaws affecting the Workstation Pro and Fusion Pro hypervisor products


VMware has issued a security advisory detailing critical flaws in its Workstation and Fusion hypervisor products after making them available to individuals for free.
On 14 May, VMware disclosed a series of security vulnerabilities in the two hypervisor solutions, providing workarounds and warning customers to patch their systems as soon as possible.
The first and most serious of these was CVE-2024-22267, a critical use-after-free vulnerability in the products’ vbluetooth device. The flaw has a CVSS rating of 9.3, the company revealed.
VMware warned that a hacker with local administrative privileges on a virtual machine could exploit the flaw to execute code as the virtual machine’s VMX process running on the host.
The second security issue, CVE-2024-22268, is a heap buffer-overflow vulnerability affecting the Shader functionality in Workstation and Fusion, rated 7.1 on the CVSS.
If exploited correctly, the flaw could give an unauthorized actor with access to a VM with 3D graphics enabled the ability to force the target system into a denial of service (DoS) condition.
Also rated 7.1 on the CVSS, VMware disclosed another high-severity vulnerability – CVE-2024-22269 – which is an information disclosure flaw in the bluetooth device that could allow an attacker with admin privileges on a VM to read sensitive information contained in the hypervisor memory.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Finally, CVE-2024-22270, is another information disclosure vulnerability with a 7.1 CVSS rating that could give attackers access to information in the hypervisor memory, this time in Workstation and Fusion’s host guest file sharing (HGFS) functionality.
Not the best timing for VMware
The day before it warned customers of the security problems affecting the two hypervisor products, VMware also announced it would be making Workstation Pro and Fusion Pro free for personal use.
Workstation Pro is VMware’s hypervisor solution for Windows and Linux devices, whereas Fusion covers customers using Mac systems.
They allow users to build ‘local virtual’ environments to install a variety of operating systems (OS) to build and test software.
The move has been touted as a gesture of goodwill by Broadcom amidst continued controversy over changes made since its acquisition of the firm last year.
RELATED WHITEPAPER
The acquisition has received stern criticism from various stakeholders due to Broadcom’s decision to overhaul the licensing structure for many of VMware’s most popular products.
Shortly after the acquisition in November 2023, Broadcom wasted no time announcing it would be axing over 50 standalone cloud services from VMware, including its popular Aria SaaS offering.
With its Workstation Pro and Fusion Pro announcement, VMware said the motivation behind the move was to “simplify how we bring VMware Desktop Hypervisor apps to market”, while ensuring both free and paid users received regular support and maintenance.
Enterprise users will find VMware has reduced its product group offerings down to a single stock keeping unit (SKU) for users who need licensing for commercial use. This simplification will eliminate over 40 other SKUs which VMware hopes will make quoting and purchasing their desktop hypervisor apps easier than ever.

Solomon Klappholz is a former staff writer for ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing, which led to him developing a particular interest in cybersecurity, IT regulation, industrial infrastructure applications, and machine learning.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Broadcom records huge growth as CEO Hock Tan hails “successful integration” of VMware
Analysis The VMware acquisition is finally paying dividends for Broadcom
By George Fitzmaurice
-
Broadcom EMEA CTO claims the company has been able to solve most of its customer issues following VMware acquisition
News Joe Baguley says the firm has been walking customers through license changes and explaining the value of VMware
By George Fitzmaurice
-
Cloud repatriation may be nipping at hyperscaler market share, but it’s a boon for VMware
News The firm’s private cloud offerings put it in a strong position to aid customers moving workloads out of the public cloud – but repatriation can’t be the only conversation
By George Fitzmaurice
-
VMware Explore 2024 live: All the news and updates as they happen
Live Blog ITPro is live on the ground in Barcelona for VMware Explore 2024 – keep tabs on all the news, updates, and announcements in our rolling coverage
By George Fitzmaurice
-
Pure Storage announces VM assessment service – and it could please beleaguered VMware customers
News The firm unveiled a new tool for managing VM costs as part of its Pure//Accelerate London 2024 event
By George Fitzmaurice
-
Is a VMware exodus looming? Disgruntled customers are actively seeking alternative providers or exploring open source options in the wake of Broadcom’s acquisition
News VMware customers say they are seriously considering alternative providers in light of the turbulence and increasing costs that followed its acquisition by Broadcom
By Solomon Klappholz
-
Broadcom wants to unlock private cloud’s potential with VMware Cloud Foundation 9
News An emphasis on simplicity matched with improved customer controls underpins the latest VCF improvements
By Rory Bathgate
-
VMware license changes could spark a wave of data center 'devirtualization'
News The increased costs associated with Broadcom’s VMware acquisition is one of the key drivers behind this predicted shift
By George Fitzmaurice