VYPR
patchPublished Oct 8, 2026· 1 source

PoC Released for Critical VMware VMXNET3 Flaw Enabling Guest-to-Host Code Execution

A public Proof of Concept (PoC) is available for CVE-2026-59346, a critical integer overflow in VMware's VMXNET3 virtual network adapter, potentially allowing guest-to-host code execution.

A public proof of concept (PoC) has been released for CVE-2026-59346, a critical integer overflow vulnerability affecting VMware's VMXNET3 virtual network adapter. This flaw, detailed by researcher 0xCyberstan, could permit an attacker with administrative privileges within a guest virtual machine to execute code on the host system. While the current PoC demonstrates a host process crash rather than a fully functional code-execution exploit, it highlights the severity of the vulnerability.

Broadcom, which now manages VMware products, has assigned a CVSSv3 score of 9.3 to CVE-2026-59346. The company released patches for VMware Workstation and Fusion 26H1u1 on September 3, 2026, addressing the vulnerability. The advisory specifically lists VMware Workstation and Fusion versions 25H2 and 26H1 as affected. Notably, no workaround is provided by the vendor, emphasizing the need for immediate patching.

The vulnerability resides within the TCP Segmentation Offload (TSO) processing path of the host's VMware-VMX process. TSO is a technique that breaks down large network packets into smaller segments for more efficient processing. The vulnerable routine calculates the required memory for these segments by multiplying the segment count by the space needed per segment. This calculation uses a 32-bit multiplication, and when the result exceeds the representable range of a 32-bit integer, it wraps around to a smaller value. The host then allocates a buffer based on this erroneously small size.

This leads to a situation where the copy loop continues to process the original, larger segment count. Consequently, data controlled by the guest VM is written beyond the boundaries of the allocated buffer. The researcher noted that this weakness appears to be related to the same code path that was previously patched to address CVE-2025-41236. While earlier patches introduced checks to limit individual packet fields and their sum to 9,216 bytes, they failed to validate the final multiplication result, allowing inputs below these limits to still trigger an overflow.

The PoC, available on GitHub, operates as a Linux kernel module within a guest VM equipped with a VMXNET3 adapter. It directly manipulates network transmit descriptors, bypassing the guest driver's standard TSO handling, before instructing the host to process them. This exploit requires elevated privileges within the guest and is not an unauthenticated remote network attack. The resulting out-of-bounds write targets unmapped memory, causing the VMware-VMX process to crash with a segmentation fault, effectively shutting down the affected virtual machine.

The researcher's repository warns that testing this PoC can lead to the destruction of unsaved guest state. They documented a test environment using VMware Workstation Pro 25.0.1 on an Ubuntu host with an Alpine Linux guest. The Zero Day Initiative (ZDI) advisory, published on September 9, 2026, confirmed that the underlying flaw has the potential to support arbitrary code execution within the hypervisor context, assigning it a score of 7.5, which differs from Broadcom's higher assessment.

Despite the differing severity scores, the core issue remains: the public PoC confirms memory corruption and a crash, though not yet a confirmed successful guest-to-host code execution exploit. Administrators are strongly advised to update their VMware Workstation and Fusion environments to version 26H1u1 or a later supported release. It is crucial to check the host product versions, as updates to the guest operating system alone will not resolve this vulnerability. Broadcom's response matrix clearly indicates that host product updates are the necessary remedy.

The availability of this public PoC provides defenders with a concrete case for reproduction and testing. However, due to its nature, any testing should be strictly confined to authorized and isolated environments, as it is designed to deliberately crash the affected VM process. This vulnerability underscores the ongoing need for vigilance and prompt patching of virtualization software.

Synthesized by Vypr AI