ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-647: VMware Workstation VMXNET3 TSO Segmentation Integer Overflow Local Privilege Escalation Vulnerability

mediumVulnerabilityimportance 30CVE-2026-59346
AI summary · glm-5.3-flash

ZDI disclosed an integer overflow in VMware Workstation's VMXNET3 TSO code (CVE-2026-59346) enabling local privilege escalation.

Zero Day Initiative published ZDI-26-647, a CVSS 7.5 integer overflow in the VMXNET3 TSO segmentation code of VMware Workstation. A local attacker who has already obtained the ability to execute high-privileged code on the guest system can exploit the flaw to escalate privileges on affected installations. The issue is tracked as CVE-2026-59346. No exploitation is reported in the advisory.

  • Integer overflow in VMXNET3 TSO segmentation, tracked as CVE-2026-59346
  • CVSS 7.5 local privilege escalation on VMware Workstation installations
  • Requires prior execution of high-privileged code on the guest system
  • Disclosed as ZDI-26-647; no in-the-wild exploitation reported

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-59346

NVD description · AI analysis pending
PoC
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of VMware Workstation. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-59346.

This source does not provide full text. Read it at zerodayinitiative.com.