CVE-2026-41703
Awaiting Analysis Awaiting Analysis - Queue

Out-of-Bounds Read in VMware ESX Workstation and Fusion

Vulnerability report for CVE-2026-41703, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: VMware

Description

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
vmware esx *
vmware workstation *
vmware fusion *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds read vulnerability in VMware ESX, Workstation, and Fusion. A malicious actor with VM deployment privileges could trigger this issue, leading to information disclosure or a Denial-of-Service (DoS) condition on the host process. On Workstation and Fusion, the impact is limited to information disclosure.

Detection Guidance

This vulnerability cannot be directly detected via commands as it requires VM deployment privileges to trigger. Monitor VMware logs for crashes or unusual activity in ESX, Workstation, or Fusion processes. Check for out-of-bounds read errors in system logs after VM operations.

Impact Analysis

If exploited, this vulnerability could allow an attacker to read sensitive data from memory or crash the host process, causing a DoS. The impact varies by product: ESX may face DoS or information disclosure, while Workstation and Fusion are limited to information disclosure.

Compliance Impact

This vulnerability primarily causes information disclosure or Denial-of-Service (DoS) conditions, which could lead to unauthorized access to sensitive data. For GDPR, this may result in a data breach requiring notification under Article 33. For HIPAA, it could compromise protected health information, necessitating breach assessment and mitigation under the Security Rule.

Mitigation Strategies

Apply the latest security patches from VMware to address the out-of-bounds read vulnerability. Ensure VM deployment privileges are restricted to authorized users only. Monitor for unusual host process behavior or crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-41703. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart