VMware patched a vulnerability in Workstation and Fusion that could allow an attacker to run code on a host machine.
Source: Threadpost