← Back to blog

Critical VMware Flaw Exposes Host Systems to Privileged VM Users

A critical integer-overflow flaw in VMware Workstation and Fusion allows privileged VM users to execute arbitrary host code. Broadcom has released patches to address the vulnerability.

TL;DR

  • Broadcom fixed CVE-2026-59346, a critical flaw in VMware Workstation and Fusion.
  • The vulnerability has a CVSS score of 9.3 and allows arbitrary code execution on the host.
  • Attackers need elevated privileges within a VM to exploit the issue.
  • Organizations using these tools should apply updates immediately.
  • The flaw impacts virtualization environments used for development and testing.

Broadcom has disclosed and patched a high-severity vulnerability affecting VMware Workstation and Fusion products. Tracked as CVE-2026-59346, the flaw enables malicious actors with administrative access inside a virtual machine to compromise the underlying host system.

This vulnerability poses significant risk to developers, testers, and IT professionals who rely on VMware’s desktop virtualization tools. Exploitation could lead to full system compromise, data theft, or lateral movement within enterprise networks.

Vulnerability Details

  • CVE-2026-59346 is an integer-overflow vulnerability with a CVSS score of 9.3.
  • It affects both VMware Workstation (Linux and Windows) and VMware Fusion (macOS).
  • An attacker must already possess administrative privileges within a guest VM.
  • Successful exploitation leads to arbitrary code execution on the host operating system.
  • The flaw resides in how the hypervisor handles memory allocation during specific operations.

Impact and Mitigation

  • Organizations running unpatched versions are exposed to potential host-level breaches.
  • Immediate update to the latest supported version is recommended.
  • VMs should be treated as potentially compromised if accessed by untrusted administrators.
  • Network segmentation between VMs and critical infrastructure reduces lateral movement risks.
  • Review user permissions and audit logs for unusual activity related to VM administration.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Critical VMware Flaw Exposes Host Systems to Privileged VM Users — Agent Breach Blog | Agent Breach