Vulnerability Management

Broadcom patches critical VMware Workstation and Fusion VM escape vulnerabilities

Signage is displayed outside the Broadcom offices on June 7, 2018, in San Jose, Calif. (Photo by Justin Sullivan/Getty Images)

Broadcom has released security advisories addressing two critical vulnerabilities in VMware Workstation and Fusion products. These flaws allow for potential code execution on the host system from within a virtual machine, with no existing workarounds. Users are urged to update to the latest version immediately to mitigate these risks, with further coverage provided by Security Affairs.

The first vulnerability, CVE-2026-59346, is a critical integer-overflow flaw within the VMXNET3 virtual network adapter. Exploiting this requires local administrator privileges inside the virtual machine and could allow an attacker to execute arbitrary code on the host operating system. The second vulnerability, CVE-2026-59347, is a stack-based buffer overflow in the Host-Guest File System (HGFS) component. This also requires local administrator privileges within the virtual machine and could enable an attacker to execute code with the privileges of the VMX process on the host.

Both vulnerabilities affect VMware Workstation and Fusion versions 25H2 and 26H1, impacting users on Windows, Linux, and macOS. Broadcom has released version 26H1u1 to address these issues.

Source: Security Affairs

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds