{"id":"CVE-2026-59347","title":"VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS","summary":"VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX pr…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-121"],"vendor":"VMware","product":"VMware Workstation","affected":["workstation >= 25H2 <= 26H1","fusion >= 25H2 <= 26H1"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T06:16:35.700","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59347","references":[{"url":"https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/security-advisories/0/38288","label":"security@vmware.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-07T08:20:03.936Z","slug":"CVE-2026-59347","body":"## Overview\n\nVMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.\n\nAffected versions:\n- VMware Workstation: 25H2, 26H1 (fixed in 26H1u1)\n- VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}