Exploitation requires the attacker to have valid credentials and administrative
Broadcom released security updates on September 5, 2026, addressing two vulnerabilities in VMware Workstation and Fusion. The most severe flaw, tracked as CVE-2026-59346 with a CVSS score of 9.3, allows attackers with administrative access to virtual machines to execute arbitrary code on the host system under specific conditions. This integer overflow vulnerability affects both Workstation and Fusion products across supported platforms. The vulnerability stems from improper handling of shared folder configurations within virtual machines. When a VM administrator manipulates certain parameters related to shared folders, it can trigger an integer overflow leading to memory corruption.
Latest news
Pixxel Secures $100 Million to Expand Hyperspectral Satellite Imaging
Google Photos Introduces AI-Powered Wardrobe Planning and Manual Library Organization
YouTube glitch caught by casual user using AI tools
Apple Teases New iPhone 18 Pro Models Ahead of September EventExploitation requires the attacker to have valid credentials and administrative privileges inside the guest VM, limiting remote attack scenarios but posing significant risk in shared or multi-tenant environments. How the Integer Overflow Enables Host Escape The flaw occurs during the processing of symbolic links in shared folders where length validation fails to account for edge cases in buffer allocation. By crafting a malicious shared folder path, an attacker can overwrite critical memory structures, potentially gaining execution privileges equivalent to the VMware host service. Broadcom noted that successful exploitation could allow installation of malware, data theft, or further lateral movement within the host environment. Are All VMware Users at Equal Risk? No, the attack requires local administrative access to a virtual machine, which reduces the likelihood of widespread automated exploitation.
However, environments where users routinely grant VM admin privileges—such as development labs, training systems, or poorly restricted cloud instances—face elevated risk.
Broadcom emphasized that the vulnerability does not affect ESXi or v Sphere
Broadcom emphasized that the vulnerability does not affect ESXi or v Sphere hypervisors, confining the impact to desktop virtualization products. Broadcom recommends immediate application of the patches released in VMware Workstation 17.5.2 and Fusion 13.5.2. Users should also review shared folder configurations and restrict VM administrative privileges to trusted individuals. Until patched, disabling shared folders where not required can reduce exposure. The company confirmed no active exploitation has been observed in the wild as of the advisory release. Frequently Asked Questions What versions of VMware Workstation and Fusion are affected? Versions prior to Workstation 17.5.2 and Fusion 13.5.2 are vulnerable to CVE-2026-59346. Earlier releases lack the necessary integer overflow fixes in the shared folder module.
Can this vulnerability be exploited remotely without VM access? No, exploitation requires authenticated administrative access inside the guest virtual machine. Remote code execution without prior VM compromise is not possible based on the current analysis.
Is there a workaround if patching is delayed? Administrators can disable shared folders in VM settings or restrict VM admin rights to minimize risk. However, applying the official patches remains the only complete mitigation recommended by Broadcom.
Comments
Leave a comment