CVE-2026-41703
Received Received - Intake

Out-of-Bounds Read in VMware ESX Workstation and Fusion

Vulnerability report for CVE-2026-41703, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: VMware

Description

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
vmware esx *
vmware workstation *
vmware fusion *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds read vulnerability in VMware ESX, Workstation, and Fusion. A malicious actor with VM deployment privileges could trigger this issue, leading to information disclosure or a Denial-of-Service (DoS) condition on the host process. On Workstation and Fusion, the impact is limited to information disclosure.

Impact Analysis

If exploited, this vulnerability could allow an attacker to read sensitive data from memory or crash the host process, causing a DoS. The impact varies by product: ESX may face DoS or information disclosure, while Workstation and Fusion are limited to information disclosure.

Mitigation Strategies

Apply the latest security patches from VMware to address the out-of-bounds read vulnerability. Ensure VM deployment privileges are restricted to authorized users only. Monitor for unusual host process behavior or crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-41703. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart