Sceawere
Vulnerability Detail
CVE-2026-59347UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
HGFS Stack-Based Buffer Overflow
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 4h ago
- Vendor
- VMware
- Product
- VMware Workstation
- Attack Type
- CWE-121 Stack-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-07T06:16:35.700Z",
"pubdate": "2026-10-07T06:16:35.700Z",
"executiveSummary": "A critical stack-based buffer-overflow vulnerability exists within the Host Guest File System (HGFS) component of VMware Workstation and VMware Fusion. The vulnerability allows an attacker who has already obtained local administrative privileges within a guest virtual machine to escape the guest sandbox and achieve arbitrary code execution on the host operating system.\nThe flaw resides within the VMX process, which facilitates the interaction between the guest virtual machine and the host system. By triggering the overflow, an attacker can overwrite adjacent memory on the stack to redirect the control flow of the VMX process.\nThe risk implication is severe, as successful exploitation results in full host-level compromise, effectively breaking the isolation barrier between the virtualized environment and the host system. The vulnerability affects VMware Workstation and VMware Fusion versions 25H2 and 26H1. Remediation requires upgrading the affected software to version 26H1u1 or later.\nThis exploit necessitates prior administrative access inside the guest, limiting the attack surface to scenarios where the guest environment has been previously compromised. No network exposure is required to trigger the vulnerability, as the exploit is executed via local inter-process communication between the guest and the host.",
"technicalDetails": "The vulnerability is localized to the HGFS component, which is responsible for managing file sharing between the guest virtual machine and the host. The issue is identified as a stack-based buffer overflow, occurring when the HGFS logic fails to properly validate the length of input data provided by the guest before writing it to a stack-allocated buffer within the VMX process.\nThe VMX process functions as the core virtualization engine on the host. When the guest OS interacts with HGFS services, it sends requests through the VMware device interface. If these requests contain crafted, oversized data payloads, the HGFS handler functions may trigger a memory write operation that exceeds the allocated boundaries of the local stack buffer. Because this occurs within the VMX process context on the host, the overflow allows the attacker to corrupt return addresses, function pointers, or saved frame pointers on the stack.\nThe attack flow follows a structured trajectory: First, the attacker must have administrative control within the guest OS to interact directly with the VMware virtual device drivers that interface with HGFS. Second, the attacker crafts a malicious payload encapsulated in an HGFS protocol request designed to trigger the overflow condition during processing by the host's VMX process. Third, upon receipt, the vulnerable HGFS code performs an unbounded or insufficiently bounded memory copy operation, overwriting critical stack data. Finally, the attacker achieves arbitrary code execution by redirecting the instruction pointer to a payload or a ROP (Return Oriented Programming) chain residing in host memory.\nThe exploitation of this vulnerability results in code execution running with the privileges of the VMX process on the host operating system. This grants the attacker host-level access, bypassing the security boundaries of the hypervisor. This vulnerability affects VMware Workstation versions 25H2 and 26H1, and VMware Fusion versions 25H2 and 26H1. The flaw is specifically addressed in version 26H1u1. Because the VMX process is responsible for the integrity of the guest-host interface, the compromise is absolute regarding host-to-guest isolation, rendering host-based security controls ineffective once the host process is hijacked."
}