The Hypervisor Escape Comes to VMware: CVE-2026-47876 May Let a Guest VM Run Code on the ESX Host
Three times this year the hosting industry has watched a guest-to-host escape land on the KVM side of the fence: ITScape on arm64 in June, then Januscape and Zapscape in the same x86 shadow-paging code. Now it is VMware’s turn. CVE-2026-47876, a critical out-of-bounds write in the VMXNET3 virtual network adapter, may let an attacker with administrative privileges inside a guest virtual machine…
评论
?
参与讨论