Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
A critical security flaw has been disclosed in VMware Workstation and Fusion, according to The Hacker News. The vulnerability enables virtual machine administrators to execute code on the host operating system. This type of flaw, often referred to as a 'guest-to-host escape,' could allow an attacker with administrative privileges inside a VM to compromise the underlying host. The report does not specify affected versions or provide a CVE identifier, but it emphasizes the severity of the issue. The discovery highlights ongoing risks in virtualization platforms, where isolation between guest and host is a fundamental security boundary. Organizations using VMware Workstation or Fusion for development, testing, or production workloads should be aware of the potential for host compromise. The source does not mention any patches or mitigation steps, so the exact remediation status remains unclear.
VM admins could escape the VM and execute code on the host, breaking isolation.