<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vmware on CuraSec</title><link>https://curasec.metacog.co.kr/tags/vmware/</link><description>Recent content in Vmware on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 06 Sep 2026 14:08:28 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/vmware/index.xml" rel="self" type="application/rss+xml"/><item><title>Critical VMware Workstation/Fusion VM Escape Allows Host Code Execution</title><link>https://curasec.metacog.co.kr/insights/2026-09-06-critical-vmware-workstation-and-fusion-flaw-lets-vm-admins-e/</link><pubDate>Sun, 06 Sep 2026 14:08:28 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-06-critical-vmware-workstation-and-fusion-flaw-lets-vm-admins-e/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public PoC on GitHub for this CVSS 9.3 integer-overflow VM escape (CVE-2026-59346) makes exploitation practical even without a KEV listing; patch VMware Workstation and Fusion to the latest Broadcom-released versions immediately, prioritizing developer and security-lab machines where Workstation is commonly deployed.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> With a public PoC available, build host-side detections for anomalous process spawning from VMware Workstation parent processes, which would indicate a VM-to-host breakout attempt; the local elevated-privilege prerequisite means exploitation is a post-compromise step worth hunting for in dev-heavy environments.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A VM escape in desktop virtualization software (Workstation/Fusion, not ESXi) is a meaningful but not board-level event; note the risk for developer workstation fleets and confirm engineering is tracking the patch rollout.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-59346 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>