VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

Project Subscriptions

Vendors Products
Cloud Foundation Subscribe
Telco Cloud Platform Subscribe
Vsphere Foundation Subscribe
Workstation Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware cloud Foundation
Vmware esx
Vmware fusion
Vmware telco Cloud Platform
Vmware vsphere Foundation
Vmware workstation
Vendors & Products Vmware
Vmware cloud Foundation
Vmware esx
Vmware fusion
Vmware telco Cloud Platform
Vmware vsphere Foundation
Vmware workstation

Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.
Title Out-of-bounds read vulnerability
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-30T15:09:25.467Z

Reserved: 2026-04-22T06:21:22.982Z

Link: CVE-2026-41703

cve-icon Vulnrichment

Updated: 2026-07-30T15:08:43.618Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T13:59:38Z

Weaknesses