CVE-2026-47876: VMXNET3 out-of-bounds write vulnerability
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47876?
The severity of CVE-2026-47876 is classified as critical with a score of 9.3.
How does CVE-2026-47876 affect VMware ESX?
CVE-2026-47876 affects VMware ESX by allowing a malicious actor with local administrative privileges to exploit an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter.
What can an attacker achieve by exploiting CVE-2026-47876?
An attacker can potentially execute code on the host by exploiting CVE-2026-47876.
Is the VMXNET3 virtual network adapter the only component affected by CVE-2026-47876?
Yes, only the VMXNET3 virtual network adapter is affected; non-VMXNET3 virtual adapters are not impacted by this vulnerability.
What is the required privilege level to exploit CVE-2026-47876?
An attacker must have local administrative privileges on the virtual machine to successfully exploit CVE-2026-47876.