hacker-news · Crawled Sep 5, 2026

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Read original article ↗

AI Summary

Broadcom has patched two security vulnerabilities in VMware Workstation and Fusion, including a critical integer-overflow flaw (CVE-2026-59346) that could allow a local attacker with administrative privileges on a virtual machine to execute arbitrary code on the host. The second vulnerability is a stack-based buffer overflow in HGFS (CVE-2026-59347) that can also be exploited by a local admin to run code in the context of the VMX process on the host. Both vulnerabilities require local admin access within the VM, but could be leveraged after initial compromise via phishing or misconfigurations. The updates apply to versions 25H2 and 26H1, with fixes included in 26H1u1 releases. While no known in-the-wild exploitation of these specific flaws has been observed, recent VMware vCenter vulnerabilities have been actively exploited, including by a China-nexus APT actor.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.