Broadcom released security patches for three critical vulnerabilities spanning VMware ESX, vCenter, Workstation, and Fusion. These flaws enable unauthenticated attackers to bypass authentication, execute arbitrary code, and escape virtual machine isolation.

CVE-2024-59309 tops the threat list with a CVSS score of 9.8. This authentication bypass affects VMware vCenter and allows network-accessible attackers to gain administrative privileges without valid credentials. Exploitation requires only network access, making this remotely exploitable from untrusted networks.

The second critical flaw permits arbitrary code execution on ESX and vCenter systems. Attackers who authenticate to these platforms can run malicious commands with hypervisor-level privileges. This combination of authentication bypass plus code execution means a threat actor could compromise an entire virtualized infrastructure in a single attack chain.

The third critical vulnerability enables VM escape on Workstation and Fusion. This flaw allows guest virtual machines to break out of their isolation and execute code on the host system. VM escape attacks bypass the fundamental security boundary between guest and host, granting attackers access to all virtual machines running on that system and potentially the underlying hardware.

Organizations running these VMware products face severe operational risk. Compromised vCenter servers represent complete datacenter takeover capability. Compromised ESX hosts allow attackers to access all running workloads. VM escape vulnerabilities threaten hybrid environments where untrusted workloads share hardware with sensitive systems.

Broadcom provided patches across all affected products. Organizations should treat CVE-2024-59309 as requiring immediate patching given its unauthenticated, network-exploitable nature and maximum severity rating. Production environments using vCenter should prioritize updates before external threat actors weaponize this flaw at scale.

The virtualization layer remains a critical attack surface. These flaws