CVE-2026-22722: VMware Workstation for Windows null pointer dereference may allow an authenticated user to trigger a crash
A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22722?
CVE-2026-22722 is a medium severity vulnerability that can lead to a null pointer dereference and cause application crashes.
How do I fix CVE-2026-22722?
To remediate CVE-2026-22722, apply the latest patches provided by VMware for Workstation.
Who is affected by CVE-2026-22722?
CVE-2026-22722 affects users of VMware Workstation on Windows who have authenticated user privileges.
What type of vulnerability is CVE-2026-22722?
CVE-2026-22722 is classified as a null pointer dereference vulnerability.
Can a remote attacker exploit CVE-2026-22722?
No, CVE-2026-22722 requires authenticated user privileges, meaning only local users can exploit this vulnerability.