The affected products are VMware Workstation and Fusion versions 25H2 and 26H1. The overall risk/impact is high, as these vulnerabilities can be exploited by an attacker with local administrative privileges on a virtual machine to execute code on the host. (CVSS 9.3 — Severity): This vulnerability is an integer-overflow vulnerability that can be exploited by a local attacker with elevated privileges to run arbitrary code.
A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. (CVSS 8.1 — Severity): This vulnerability is a stack-based buffer-overflow vulnerability in HGFS that can be exploited by a bad actor with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.[/subscribe_to_unlock_form]
The affected products are VMware Workstation and Fusion versions 25H2 and 26H1. The overall risk/impact is high, as these vulnerabilities can be exploited by an attacker with local administrative privileges on a virtual machine to execute code on the host. (CVSS 9.3 — Severity): This vulnerability is an integer-overflow vulnerability that can be exploited by a local attacker with elevated privileges to run arbitrary code.
A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. (CVSS 8.1 — Severity): This vulnerability is a stack-based buffer-overflow vulnerability in HGFS that can be exploited by a bad actor with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.[emaillocker id="1283"]
Administrators should ensure they have applied the latest security updates for VMware Workstation and Fusion to prevent potential exploitation. :And, with the latter suspected to be weaponized by a China-nexus advanced persistent threat (APT) actor.
We recommend you to update VMware Workstation to given version link: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38288
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1195.002 | Supply Chain Compromise | Compromise Software Supply Chain |
The following reports contain further technical details:
[/emaillocker]