Interestana
Home/News/VMware Workstation, Fusion Flaw Allows Host Code Execution
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

VMware Workstation, Fusion Flaw Allows Host Code Execution

VMware Workstation, Fusion Flaw Allows Host Code Execution

Broadcom has issued security updates to address two vulnerabilities affecting VMware Workstation and VMware Fusion, two virtualization software products that allow users to run multiple operating systems on a single physical computer. One of these flaws is classified as critical, carrying a CVSS score of 9.3, and poses a significant risk of arbitrary code execution on the host system under specific circumstances. This critical vulnerability, identified as CVE-2026-59346, is an integer overflow vulnerability. It can be exploited by a local attacker who has already obtained elevated privileges within the virtual machine environment. Such an attacker could leverage this flaw to execute arbitrary code on the host operating system, effectively gaining control over the underlying hardware and its resources.

The second vulnerability, tracked as CVE-2026-59347, is rated as important and has a CVSS score of 7.7. This flaw is a use-after-free vulnerability, which can also lead to arbitrary code execution. Similar to the critical flaw, this vulnerability requires a local attacker with elevated privileges within the virtual machine to exploit it successfully. The use-after-free condition arises when a program attempts to access memory that has already been deallocated, leading to unpredictable behavior and potential security breaches.

VMware Workstation is a desktop hypervisor application developed by VMware that allows users to run multiple operating systems simultaneously on a single PC. VMware Fusion is its counterpart for macOS. Both products are widely used by developers, IT professionals, and security researchers for testing, development, and running legacy applications. The ability for an attacker to execute code on the host system from within a virtual machine bypasses the isolation that virtualization is designed to provide, making these vulnerabilities particularly concerning.

Broadcom, which acquired VMware in November 2023, has provided patches and workarounds for these issues. Users of VMware Workstation and Fusion are strongly advised to apply the available security updates as soon as possible to mitigate the risks associated with these vulnerabilities. The company's advisory details the specific versions affected and the steps required to update the software. The timely release of these patches underscores the ongoing efforts by Broadcom to secure the VMware product suite following its acquisition.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next