Broadcom Patches Critical RCE in VMware Workstation, Fusion
Broadcom patched two vulnerabilities in VMware Workstation and Fusion, including a critical flaw that lets a VM administrator execute code on the host system.

Confirmed. Broadcom has shipped security updates for VMware Workstation and VMware Fusion, addressing two vulnerabilities. One is rated critical. It allows a virtual machine administrator to execute code on the underlying host.
Advisory published September 5. Details via The Hacker News. Full version specifics and CVE identifiers are in Broadcom’s security advisory portal.
The vulnerability
VMware Workstation and Fusion are desktop hypervisors. Workstation runs on Windows and Linux; Fusion runs on macOS. Both let users run guest operating systems on a host machine.
The critical flaw enables a VM administrator, with control of a guest, to run code on the host. That is guest-to-host breakout. An attacker who has administrative access inside the virtual machine can reach processes and data outside it, on the physical machine. Confidence: confirmed per Broadcom’s advisory. Exploitation in the wild: unconfirmed as of this writing.
A second vulnerability is patched in the same release. Severity and class for that second flaw are not specified in available reporting.
What to do
Patch is out. Check the Broadcom advisory for the affected version ranges and updated builds. No documented workaround is stated as sufficient in place of the update.
Running an unpatched build past this week. That is a choice, not bad luck.
Related coverage
In late July, Broadcom patched three critical VMware flaws in vCenter and ESXi, including auth bypass and VM escape. A week earlier, critical auth bypass and RCE were fixed in the same product line. Those were server-side products. Workstation and Fusion are the desktop virtualization surface. Separate targets, same patch urgency.
Found this useful? Share it.


