ZDI-26-495: (Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-47876.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-495?
ZDI-26-495 has been assigned a CVSS rating of 8.2, indicating a high severity level.
How do I fix ZDI-26-495?
To mitigate the risk of ZDI-26-495, users should apply the latest patches released by VMware for ESXi.
What type of attack does ZDI-26-495 allow?
ZDI-26-495 allows local attackers to escalate privileges on affected installations of VMware ESXi.
What is the impact of exploiting ZDI-26-495?
Exploiting ZDI-26-495 can lead to unauthorized access and increased privileges on the affected guest system.
Who is affected by ZDI-26-495?
Users of VMware ESXi with unpatched versions are vulnerable to ZDI-26-495.