ZDI-26-190: (Pwn2Own) VMware Workstation PVSCSI Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of VMware Workstation. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2025-41238.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-190?
The severity of ZDI-26-190 is classified as high due to its potential for local privilege escalation.
How do I fix ZDI-26-190?
To fix ZDI-26-190, you should apply the latest security patches provided by VMware for the Workstation software.
Who is affected by ZDI-26-190?
ZDI-26-190 affects local users of VMware Workstation who have high-privileged code execution capabilities.
What type of vulnerability is ZDI-26-190?
ZDI-26-190 is a heap-based buffer overflow vulnerability that leads to local privilege escalation.
What actions can an attacker take with ZDI-26-190?
An attacker exploiting ZDI-26-190 can escalate their privileges on affected installations of VMware Workstation.