Skip to main content
Vulnerability Database/CVE-2026-59347

CVE-2026-59347: VMware Workstation Buffer Overflow Vulnerability

CVE-2026-59347 is a stack-based buffer overflow in VMware Workstation and Fusion HGFS that enables local admins to execute code as VMX process. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-59347 Overview

CVE-2026-59347 is a stack-based buffer overflow [CWE-121] in the Host-Guest File System (HGFS) component of VMware Workstation and Fusion. A local attacker with administrative privileges inside a guest virtual machine can trigger the overflow to execute code in the context of the host's VMX process. The flaw crosses the guest-to-host trust boundary, resulting in a scope change where exploitation on the guest impacts the host system. Broadcom disclosed the issue in Security Advisory #38288 and shipped fixes in the 26H1u1 release train for both Workstation and Fusion.

Critical Impact

Successful exploitation allows guest-to-host code execution as the VMX process, breaking virtual machine isolation on affected hypervisor hosts.

Affected Products

  • VMware Workstation 25H2 and 26H1 (fixed in 26H1u1)
  • VMware Fusion 25H2 and 26H1 (fixed in 26H1u1)
  • Hosts running vulnerable Workstation or Fusion builds with HGFS enabled

Discovery Timeline

  • 2026-10-07 - CVE-2026-59347 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-59347

Vulnerability Analysis

The vulnerability resides in HGFS, the component that brokers file-sharing operations between a guest virtual machine and the host. HGFS requests originating in the guest are parsed by the VMX process running on the host. A malformed request produces a stack-based buffer overflow during this parsing, corrupting the saved return state of the host-side handler.

Because the VMX process runs on the host operating system, successful exploitation shifts code execution out of the guest and onto the host. This breaks the isolation boundary that virtualization is intended to enforce. The CVSS scope change reflects that the attacker's impact extends beyond the vulnerable guest.

Exploitation requires local administrative privileges inside the guest. That precondition narrows the attacker population but does not eliminate the risk in multi-tenant lab, developer, or malware-analysis environments where guests are routinely treated as untrusted.

Root Cause

The root cause is improper bounds checking when HGFS copies attacker-controlled data from a guest request into a fixed-size stack buffer in the VMX process. The condition maps to [CWE-121] Stack-Based Buffer Overflow. Broadcom has not published offset-level technical detail in advisory #38288.

Attack Vector

An attacker with administrator rights on a guest issues a crafted HGFS request through the shared-folders channel. The VMX process on the host receives and parses the request, overflows the stack buffer, and executes attacker-controlled logic in the host user context of VMX. The attack vector is local to the guest but the resulting code execution occurs on the host.

No public proof-of-concept, exploit, or exploitation activity is listed in CISA KEV at the time of publication. Technical details are available in the Broadcom Security Advisory #38288.

Detection Methods for CVE-2026-59347

Indicators of Compromise

  • Unexpected termination or crash of the vmware-vmx process on the host, which may indicate a failed exploitation attempt against the HGFS parser.
  • New or anomalous child processes spawned by vmware-vmx on the host, particularly shells, scripting engines, or network tools.
  • Guest systems with shared folders enabled where a local administrator has recently been added or where unexpected binaries interact with HGFS.

Detection Strategies

  • Monitor host-side process ancestry for vmware-vmx spawning non-standard children, which is a reliable signal of post-exploitation activity.
  • Alert on repeated vmware-vmx crashes or Windows Error Reporting entries, as fuzzing-style exploitation attempts generate unstable states.
  • Inventory Workstation and Fusion installations and flag any build older than 26H1u1 for prioritized remediation.

Monitoring Recommendations

  • Capture EDR telemetry on hosts running Workstation or Fusion, with specific attention to module loads and memory protection changes inside vmware-vmx.
  • Log and review HGFS configuration changes across managed developer and lab endpoints.
  • Correlate guest administrative actions with host-side VMX process events to surface guest-to-host anomalies.

How to Mitigate CVE-2026-59347

Immediate Actions Required

  • Upgrade VMware Workstation and Fusion to version 26H1u1 or later on every affected host.
  • Where immediate patching is not feasible, disable HGFS shared folders on all virtual machines until the host is updated.
  • Restrict administrative access inside guest virtual machines to trusted users only, reducing the population able to meet the exploitation precondition.

Patch Information

Broadcom addressed CVE-2026-59347 in VMware Workstation 26H1u1 and VMware Fusion 26H1u1. Earlier 25H2 and 26H1 builds remain vulnerable. Refer to the Broadcom Security Advisory #38288 for the authoritative fixed-version list and download guidance.

Workarounds

  • Disable the HGFS shared-folders feature on each virtual machine through the VM settings dialog.
  • Remove or restrict shared-folder mounts inside guest operating systems to prevent HGFS request flows.
  • Isolate hosts running untrusted or analysis-oriented guests on segmented networks until patching is complete.
bash
# Disable shared folders on a VM via vmrun (run on the host)
vmrun disableSharedFolders "/path/to/vm.vmx"

# Alternatively, set in the .vmx configuration file:
# isolation.tools.hgfs.disable = "TRUE"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.