
TRC analysis shows attackers exploiting CVE-2024-38812 and CVE-2024-38813 to achieve VM-to-host escape in VMware Workstation/Fusion environments. Once hypervisor access is gained, lateral movement to other VMs becomes trivial. Runtime segmentation helps contain post-compromise activity across virtualized infrastructure. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/critical-vmware-workstation-fusion-flaw-cve-2026-59346
Post summary
Attackers are actively exploiting CVE‑2024‑38812 and CVE‑2024‑38813 to escape from VMware Workstation/Fusion VMs to the host, enabling easy lateral movement across virtual infrastructure.

