Stack-based buffer overflow in VMware Fusion and VMware Workstation - CVE-2026-59347

 

Stack-based buffer overflow in VMware Fusion and VMware Workstation - CVE-2026-59347

Published: September 3, 2026


Vulnerability identifier: #VU146873
CSH Severity: Low
CVSS v4: 5 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2026-59347
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute code as the virtual machine's VMX process running on the host.

The vulnerability exists due to stack-based buffer overflow in HGFS when handling HGFS operations from a virtual machine. A remote user with administrative privileges on the guest can execute arbitrary code as the virtual machine's VMX process running on the host.


Affected software

VMware Fusion
VMware Workstation

How to mitigate CVE-2026-59347

Install security update from vendor's website.

VMware Fusion - update to 26H1u1
VMware Workstation - update to 26H1u1

External References

Related Security Bulletins