AI Security AI安全 3h ago Updated 1h ago 更新于 1小时前 42

VMware Workstation and Fusion Updates Patch Critical Vulnerability VMware Workstation 和 Fusion 更新修复关键漏洞

Broadcom patched two critical vulnerabilities in VMware Workstation and Fusion: CVE-2026-59346 (CVSS 9.3, integer overflow) and CVE-2026-59347 (CVSS 8.1, stack-based buffer overflow) Both flaws allow a malicious actor with local admin privileges inside a VM to execute arbitrary code on the host, representing a critical VM escape risk The vulnerabilities affect VMware Workstation and Fusion versions 25H2 and 26H1, with fixes available in version 26H1u1 No workarounds exist; Broadcom strongly reco Broadcom发布VMware Workstation和Fusion安全补丁,修复两个关键级漏洞 CVE-2026-59346(CVSS 9.3)为整数溢出漏洞,可导致宿主机任意代码执行 CVE-2026-59347(CVSS 8.1)为栈缓冲区溢出漏洞,可导致VMX进程权限提升 漏洞影响25H2和26H1版本,已在26H1u1中修复,目前无在野利用报告 VMware产品历史上频繁被利用,CISA KEV列表中已有20+个VMware漏洞

65
Hot 热度
60
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • Broadcom patched two critical vulnerabilities in VMware Workstation and Fusion: CVE-2026-59346 (CVSS 9.3, integer overflow) and CVE-2026-59347 (CVSS 8.1, stack-based buffer overflow)
  • Both flaws allow a malicious actor with local admin privileges inside a VM to execute arbitrary code on the host, representing a critical VM escape risk
  • The vulnerabilities affect VMware Workstation and Fusion versions 25H2 and 26H1, with fixes available in version 26H1u1
  • No workarounds exist; Broadcom strongly recommends immediate patching, though no active exploitation in the wild has been reported
  • VMware has over two dozen vulnerabilities on CISA's Known Exploited Vulnerabilities list, underscoring the sector's ongoing security challenges

Why It Matters

VM escape vulnerabilities are among the most dangerous class of flaws in virtualization, as they allow attackers to pivot from a compromised guest VM to the underlying host system, potentially compromising all workloads on that machine. For AI practitioners running models in virtualized environments, this represents a direct threat to infrastructure security and data confidentiality. The absence of workarounds makes timely patching a critical operational priority.

Technical Details

  • CVE-2026-59346 (CVSS 9.3): An integer overflow vulnerability that can be exploited by an attacker with local administrative privileges on a VM equipped with a VMXNET3 virtual network adapter, leading to arbitrary code execution on the host
  • CVE-2026-59347 (CVSS 8.1): A stack-based buffer overflow vulnerability allowing a similarly privileged attacker to execute code as the VM's VMX process running on the host, with different exploitation conditions than CVE-2026-59346
  • Both vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1; the fix is included in version 26H1u1
  • No workarounds are available for either flaw, and Broadcom reports no evidence of in-the-wild exploitation at this time
  • The vulnerabilities were reported privately to Broadcom, consistent with responsible disclosure practices

Industry Insight

  • Organizations running VMware Workstation or Fusion should prioritize immediate patching to version 26H1u1, as the VM escape nature of these flaws makes them high-value targets for threat actors
  • The pattern of VMware vulnerabilities accumulating on CISA's KEV list suggests virtualization platforms remain a persistent attack surface; consider network segmentation and least-privilege access for VMs as defense-in-depth measures
  • AI practitioners deploying workloads in virtualized environments should audit their VMware versions and assess whether any VMs with admin-level access could serve as an initial foothold for host compromise

TL;DR

  • Broadcom发布VMware Workstation和Fusion安全补丁,修复两个关键级漏洞
  • CVE-2026-59346(CVSS 9.3)为整数溢出漏洞,可导致宿主机任意代码执行
  • CVE-2026-59347(CVSS 8.1)为栈缓冲区溢出漏洞,可导致VMX进程权限提升
  • 漏洞影响25H2和26H1版本,已在26H1u1中修复,目前无在野利用报告
  • VMware产品历史上频繁被利用,CISA KEV列表中已有20+个VMware漏洞

为什么值得看

VMware作为企业级虚拟化核心平台,其安全漏洞直接影响数据中心和云基础设施安全。这两个漏洞均可实现虚拟机逃逸,攻击者获得宿主机控制权,对虚拟化部署构成严重威胁。

技术解析

  • CVE-2026-59346是整数溢出漏洞,攻击者需具备虚拟机本地管理员权限且使用VMXNET3虚拟网卡,通过该漏洞可在宿主机执行任意代码,CVSS评分9.3
  • CVE-2026-59347是栈缓冲区溢出漏洞,同样需要本地管理员权限,但利用条件不同,可导致VMX进程以宿主机权限执行代码,CVSS评分8.1
  • 两个漏洞均影响VMware Workstation和Fusion的25H2和26H1版本,已在26H1u1中修复
  • 目前尚无已知在野利用,漏洞由私人渠道报告,但VMware产品历史上频繁被威胁行为者利用
  • CISA的KEV列表中已有20多个VMware漏洞,表明此类产品是攻击者的重点目标

行业启示

  • 虚拟化平台安全直接影响企业基础设施,VMware漏洞可导致虚拟机逃逸,威胁宿主机安全,建议立即更新到26H1u1版本
  • 由于无临时解决方案,补丁是唯一缓解措施,企业应优先安排更新计划
  • 组织应加强虚拟化环境的安全监控,特别是针对VMXNET3网卡和VMX进程的活动检测,降低被利用风险

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全