Sceawere

Vulnerability Detail

CVE-2026-59346UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

VMware VMXNET3 Integer Overflow Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
4h ago
Vendor
VMware
Product
VMware Workstation
Attack Type
CWE-190 Integer Overflow or Wraparound
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-10-07T06:16:35.543Z",
  "pubdate": "2026-10-07T06:16:35.543Z",
  "executiveSummary": "VMware Workstation and Fusion are affected by an integer-overflow vulnerability within the VMXNET3 virtual network adapter implementation.\nThis vulnerability allows an attacker possessing local administrative privileges on a virtual machine to achieve code execution on the host operating system.\nThe flaw stems from improper handling of integer operations, which can lead to memory corruption when processed by the host-side VMXNET3 component.\nSuccessful exploitation requires the attacker to have administrative access within the guest virtual machine, making this a guest-to-host breakout vector.\nThe impact is critical, as it enables unauthorized code execution on the host, potentially leading to full host system compromise, data exfiltration, or persistence.\nAffected products include VMware Workstation and VMware Fusion versions 25H2 and 26H1, necessitating immediate updates to the patched release, version 26H1u1.",
  "technicalDetails": "The vulnerability is identified as an integer-overflow residing within the VMXNET3 virtual network adapter driver. The VMXNET3 device acts as the paravirtualized network interface controller provided by VMware to guests, facilitating high-performance network communication between the virtual machine and the host hypervisor.\nThe root cause involves an arithmetic operation performed during the processing of network packets or device configuration structures within the host-side emulation of the VMXNET3 device. When the virtual machine performs specific I/O operations or transmits malformed packets, the host-side driver may experience an integer overflow. This overflow typically occurs when calculating buffer sizes or memory offsets, resulting in an undersized allocation or an out-of-bounds write operation.\nThe exploitation flow begins with the attacker gaining administrative privileges inside the guest virtual machine. With these privileges, the attacker interacts directly with the VMXNET3 virtual hardware interface. By sending carefully crafted input—such as malformed network packets or specifically formatted device commands—the attacker triggers the vulnerable arithmetic operation in the host hypervisor process.\nOnce the integer overflow is triggered, the subsequent memory operation results in a heap buffer overflow or an out-of-bounds write within the context of the host's virtual machine monitor (VMM) process. Because the VMM process operates with the privileges of the user running the VMware Workstation or Fusion application, the attacker can leverage this memory corruption to overwrite critical data structures, such as function pointers or return addresses.\nBy hijacking the control flow of the host-side process, the attacker can redirect execution to an arbitrary payload (shellcode) injected into the host memory. This grants the attacker execution capabilities on the host operating system, effectively breaking the isolation boundary between the guest and the host. The exploitation allows for the execution of arbitrary code, which carries significant post-exploitation implications, including host-level persistent access, lateral movement within the host environment, and complete bypass of guest security controls. The vulnerability specifically affects VMware Workstation and Fusion versions 25H2 and 26H1, with remediation confirmed in version 26H1u1."
}
CVE-2026-59346: VMware VMXNET3 Integer Overflow Vulnerability (CRITICAL Severity, CVSS: 9.3) | Sceawere