CVE-2026-22716
Received Received - Intake

Out-of-Bounds Write in VMware Workstation Allows Process Termination

Vulnerability report for CVE-2026-22716, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-27

Last updated on: 2026-02-27

Assigner: VMware

Description

Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to terminate certain Workstation processes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-27
Last Modified
2026-02-27
Generated
2026-07-26
AI Q&A
2026-02-27
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vmware workstation 25h1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bound read issue in VMware Workstation version 25H1 and earlier on any platform. It allows a user with non-administrative privileges inside a guest virtual machine to read limited information from the host machine where VMware Workstation is installed.

Detection Guidance

I don't know

Impact Analysis

The impact of this vulnerability is limited information disclosure from the host machine to a non-administrative user inside a guest VM. This could potentially expose sensitive data or system details, but the overall severity is low given the CVSS base score of 2.7.

Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-22716. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart