PoC Released for Critical VMware VMXNET3 Flaw Enabling Guest-to-Host Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A public proof of concept is now available for CVE-2026-59346, a critical integer overflow flaw in VMware’s VMXNET3 virtual network adapter, released by 0xCyberstan.

The flaw can allow an attacker with administrative access inside a guest virtual machine to execute code on the host. However, the published PoC shows a host process crash, not a working code-execution exploit.

Broadcom rates the vulnerability at 9.3 on the CVSSv3 scale and patched it in VMware Workstation and Fusion 26H1u1, released on September 3, 2026.

Its advisory lists Workstation and Fusion versions 25H2 and 26H1 as affected. The vendor security advisory states that no workaround is available.

The flaw sits in the TCP Segmentation Offload, or TSO, processing path within the host’s VMware-VMX process. TSO splits a large network packet into smaller segments. The vulnerable routine calculates how much memory those segments need by multiplying the segment count by the space required for each segment.

That calculation uses a 32-bit multiplication. When the result exceeds the range that 32 bits can hold, it wraps to a smaller value. The host then allocates a buffer using that reduced size.

Meanwhile, the copy loop still runs through the original segment count. Guest-controlled packet data consequently gets written beyond the allocated buffer.

The researcher links this weakness to the same code path previously patched for CVE-2025-41236. Those earlier checks limited individual packet fields and their sum to 9,216, but did not validate the final multiplication result.

PoC Released for VMware VMXNET3 Flaw

As a result, inputs below those limits could still trigger an overflow. Cyber Security News previously covered the earlier VMware VMXNET3 vulnerability, providing context for this renewed concern.

Available through the GitHub repository, the PoC runs as a Linux kernel module inside a guest with a VMXNET3 adapter. It writes network transmit descriptors directly, bypassing the guest driver’s normal TSO handling, before asking the host to process them. This requires sufficient privileges inside the guest; it is not an unauthenticated remote network attack.

The resulting out-of-bounds write reaches unmapped memory and crashes vmware-vmx with a segmentation fault, powering off the affected virtual machine.

The 0xCyberstan repository warns that testing could destroy unsaved guest state and documents a test environment using VMware Workstation Pro 25.0.1 on an Ubuntu host with an Alpine Linux guest.

The Zero Day Initiative advisory, published September 9, confirms that the underlying flaw can support arbitrary code execution in the hypervisor context.

ZDI assigns a score of 7.5, compared with Broadcom’s 9.3. Neither assessment changes the key distinction: the public release proves memory corruption and a crash, not successful guest-to-host code execution.

Administrators should install 26H1u1 or a later supported release and check host versions, rather than assuming guest operating system updates fix the issue. Broadcom’s response matrix identifies host product updates as the remedy.

For background, Cyber Security News covered the original Workstation and Fusion disclosure. The public PoC now gives defenders a concrete reproduction case. However, testing belongs only in authorized, isolated environments because it deliberately crashes the affected VM process.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post PoC Released for Critical VMware VMXNET3 Flaw Enabling Guest-to-Host Code Execution appeared first on Cyber Security News.