CVE-2026-22717: VMware Workstation out-of-bound read vulnerability
Published Feb 27, 2026
·Updated
Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed.
Affected Software
1 affected component
VMware Workstation<25H1
Event History
Feb 27, 2026
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:21 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-22717?
CVE-2026-22717 is classified as a medium severity vulnerability.
2
How do I fix CVE-2026-22717?
To fix CVE-2026-22717, upgrade VMware Workstation to version 25H2 or later.
3
Who is affected by CVE-2026-22717?
CVE-2026-22717 affects users of VMware Workstation version 25H1 and below on any platform.
4
What kind of vulnerability is CVE-2026-22717?
CVE-2026-22717 is an out-of-bound read vulnerability that can lead to limited information disclosure.
5
Can non-administrative users exploit CVE-2026-22717?
Yes, non-administrative users on a guest VM can exploit CVE-2026-22717 to access sensitive information.