HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Local Privilege Escalation in VMware Workstation VMXNET3 (CVE‑2026‑59346) Enables Hypervisor Takeover

A newly disclosed integer‑overflow bug in VMware Workstation’s VMXNET3 driver lets a malicious guest gain hypervisor‑level privileges. The issue underscores the need for continuous patch evidence to satisfy access‑control and audit requirements.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Local Privilege Escalation in VMware Workstation VMXNET3 (CVE‑2026‑59346) Enables Hypervisor Takeover

What It Is – A integer‑overflow flaw in the VMXNET3 virtual NIC driver of VMware Workstation allows a local attacker who already runs code on a guest VM to corrupt hypervisor memory and gain hypervisor‑level privileges.

Exploitability – The vulnerability requires local code execution on the guest and manual exploitation; no public exploit code is known. CVSS v3.1 7.5 (AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

Affected Products – VMware Workstation (all supported versions at the time of disclosure).

Why It Matters for Trust & Control Assurance

  • Access‑control integrity – The flaw bypasses the isolation boundary that controls rely on to separate privileged hypervisor functions from guest workloads.
  • Continuous compliance evidence – Demonstrating that hypervisor patches are applied is a concrete control‑objective evidence point that maps to multiple frameworks (e.g., NIST CSF, ISO 27001).
  • Audit‑ready posture – Enterprises must be able to prove timely remediation of privileged‑escalation vectors to satisfy auditors and regulator‑driven due‑diligence reviews.

Recommended Actions

  • Deploy VMware’s security update for Workstation immediately on all endpoints.
  • Verify patch status with an automated inventory tool and capture the results as compliance evidence.
  • Update baseline hardening guides to require VMXNET3 driver version ≥ the patched release.
  • Conduct a focused review of privileged‑access controls around hypervisor management interfaces.

Source: Zero Day Initiative advisory ZDI‑26‑647

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-647/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →