CVE-2026-22722
Received Received - Intake
Null Pointer Dereference in Windows Workstation via Authenticated User

Publication date: 2026-02-26

Last updated on: 2026-02-26

Assigner: VMware

Description
A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-26
Last Modified
2026-02-26
Generated
2026-06-16
AI Q&A
2026-02-26
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
vmware workstation From 3.2.4 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability involves a null pointer dereference error that can be triggered by a malicious actor who has authenticated user privileges on a Windows-based Workstation host.

Mitigation Strategies

To remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'.

Impact Analysis

Exploitation of this vulnerability can cause a denial of service condition by crashing the affected system or application, as indicated by the null pointer dereference error leading to high impact on availability.

Compliance Impact

I don't know

Detection Guidance

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-22722. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart