$ techbeacon▋
CVE & Exploits

VMware Releases Patches for Workstation and Fusion to Close Critical Host‑Escape Flaw

VMware Releases Patches for Workstation and Fusion to Close Critical Host‑Escape Flaw

VMware has issued security updates for its flagship desktop virtualization products, Workstation and Fusion, addressing a high‑severity vulnerability that could enable a malicious actor with administrative rights inside a virtual machine to run code on the underlying host operating system.

The flaw, identified as a privilege‑escalation and host‑escape issue, stems from insufficient isolation between the guest and host environments. Security researchers demonstrated that an attacker who gains admin access to a compromised VM could exploit the vulnerability to break out of the virtual sandbox, potentially taking control of the host machine and any other VMs running on it.

VMware first disclosed the vulnerability through its security advisory, urging users to apply the patches immediately. The updates, released for both Windows and macOS versions of Workstation and Fusion, incorporate mitigations that tighten the interaction between virtual hardware emulation and the host kernel, effectively blocking the code‑execution path exploited in the proof‑of‑concept attacks.

Virtualization platforms like VMware’s are widely used in enterprise IT, software development, and by individual users for testing and sandboxing. Because they often run privileged workloads, any weakness that bridges the guest‑host boundary can have outsized impact, especially in environments where multiple VMs share a single physical host. The recent flaw underscores the ongoing challenge of maintaining strong isolation in complex hypervisor architectures.

SecurityWeek, which first reported the issue, noted that the vulnerability was classified as critical by industry standards due to the combination of required privileges and the potential for full system compromise. VMware recommends that organizations verify the successful installation of the patches and review their VM access controls to reduce the risk of an attacker obtaining administrative rights within a guest. As virtualization continues to expand across cloud and edge deployments, timely patching and rigorous configuration hygiene remain essential defenses against similar threats.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related