Critical VMware Workstation and Fusion Integer‑Overflow (CVE‑2026‑59346) Enables Host Code Execution
What It Is – VMware Workstation and Fusion contain an integer‑overflow flaw (CVE‑2026‑59346) that allows a local user with elevated VM‑admin rights to execute arbitrary code on the underlying host OS.
Exploitability – The vulnerability scores 9.3 (Critical) on the CVSS v3.1 scale. No public exploit has been released, but the flaw is trivial to weaponise once an attacker gains VM‑admin privileges.
Affected Products – VMware Workstation 17.x (Windows/macOS/Linux) and VMware Fusion 13.x (macOS). Broadcom’s advisory notes that earlier versions are also vulnerable.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for strict privileged‑access segregation between guest‑admin and host‑admin roles – a core control‑area that maps to many frameworks (e.g., NIST CSF 2.0 “Protect – Identity Management”).
- Continuous evidence of access‑control enforcement and privileged‑session logging is essential to prove due‑diligence during audits or third‑party assessments.
- Enterprises that must show a defensible audit trail will need to capture patch‑status and configuration evidence as part of their control‑monitoring program.
Recommended Actions
- Deploy Broadcom’s security updates for Workstation and Fusion immediately.
- Review and tighten host‑level privilege assignments; enforce least‑privilege for any user granted VM‑admin rights.
- Enable and centralise host‑level logging of VM‑admin activities to provide audit‑ready evidence.
- Incorporate the patch‑status into your continuous control‑monitoring dashboard.
Source: The Hacker News – Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code