VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2016-6280
http://www.vmware.com/security/advisories/VMSA-2016-0017.html