Bg ShapeBg Shape
THREAT INTELLIGENCE

Critical Vulnerabilities in VMware Workstation and Fusion

Affected Environment
VMware Workstation and VMware Fusion, versions 25H2 and 26H1, running on any supported host platform.

Threat Overview
Critical integer-overflow and stack-based buffer-overflow vulnerabilities in VMware Workstation and Fusion allow code execution on the host.

Exposure Timeline
Newly disclosed critical vulnerabilities; fixed version 26H1u1 available now, patch before proof-of-concept exploitation emerges.

Attack Surface
VMXNET3 virtual network adapter and HGFS shared folder feature, exploitable by local administrators on guest virtual machines.

Technical Root Cause
Integer overflow in VMXNET3 handling and a stack-based buffer overflow in HGFS both enable host-level code execution.

Exploitation Pathway
Malicious actor with local admin privileges on a VM exploits the adapter or HGFS flaw for host code execution.

Operational Impact
Guest-to-host escape allowing code execution on the underlying host system running affected VMware products.

Strategic Impact
Critical risk across government and business entities of all sizes due to virtualization host compromise potential.

Required Mitigation
Upgrade VMware Workstation and Fusion to version 26H1u1 or later as soon as possible.

Incident Response Guidance
Audit VM administrative access, review host logs for anomalous VMX process activity, and restrict local admin rights.

References
Broadcom Support Portal.

Download the Full Report

Explore More of the Latest Threat Intelligence

Trusted by clients worldwide

Logo
Logo
Logo
Logo
Logo
Logo

Your 24/7 Security Partner

Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.

Awards Image
Awards Image
Awards Image
Awards Image
Awards Image
Awards Image