Thank you for your prompt follow-up.
The requested information should be in the provided ReversingLabs report link already provided below.
I've also included screenshots and supporting information.
If possible, please have Broadcom to contact me directly by phone or chat. I'll then loop in our Cybersecurity SME to review the report and answer questions
Original Message:
Sent: Aug 18, 2026 05:56 PM
From: Allan Solomon Mejia
Subject: VMware-workstation-full-17.6.4-24832109.exe Scan issues
Hi Aaron,
Thank you for providing the ReversingLabs report. I reviewed the summary, and it provides some useful additional detail.
The report is specifically detecting two Win64.Certificate.Invalid findings and two tampered signatures. It also reports digital signatures failing integrity validation and package/content integrity-validation failures. At the same time, the scan reports no known vulnerabilities, so I wouldn't interpret this report alone as confirmation that the installer contains malicious code.
Since you've also confirmed that:
- the installer came directly from the official Broadcom download source; and
- the checksum verification did not identify a mismatch,
I think this now warrants review by Broadcom Engineering/Product Security to determine exactly which embedded components/signatures are triggering the integrity failures.
The next useful step would be to identify the specific files associated with the two Win64.Certificate.Invalid detections and the two malformed-format detections. The summary report doesn't appear to expose enough component-level information to determine whether these are expected packaging/signing artifacts, legacy embedded components, or something Broadcom needs to correct.
I would therefore not delete or modify the package to work around the scanner findings. Please provide Broadcom Support with the SHA-256, ReversingLabs report, Workstation version/build (17.6.4 / 24832109), and the component-level findings if available.
Since the integrity findings are reproducible against the official Broadcom package, Broadcom is best positioned to confirm whether these are known/expected scanner findings or an issue with the distributed package.
Thanks for providing the additional evidence. This definitely helps narrow the investigation.
Original Message:
Sent: Aug 18, 2026 04:54 PM
From: Aaron NANA NONO
Subject: VMware-workstation-full-17.6.4-24832109.exe Scan issues
Hi Allan
Please see below our follow up to your suggestions
- Confirm that both installers were downloaded directly from the official Broadcom/VMware download portal. Broadcom documents the current Workstation download process through its Support Portal.
ANN: Confirmed.
- Compare the installer checksum against the checksum published for that download, if available.
ANN: No issues found
- On Windows, check Properties → Digital Signatures → Details and confirm that Windows reports the signature as valid and inspect the signer/certificate chain.
ANN: Not applicable according to our Cybersecurity department
- If the official Broadcom-downloaded binary still produces the ReversingLabs Certificate.Invalid / tampered-signature findings, provide Broadcom Support with the SHA-256 hash and these reports so they can determine whether this is expected packaging/signing behavior or something requiring remediation.
ANN: Please see below the SHA-256 and hash related to the two invalid certificates.
I've also provided a link and password to access the full report
- SHA256: a0ef9087607d9cad20b08139e73e41242e044ad5bd8cee141d3bad314586737f
- Hash: dde4ddc2556dc010ea530862f0ac8845baab333bcf1b7a9d49c231ebf36a438c
- Hash: d530f434163428dc8ff46c30149f1350e6bc517ce91c8b27f23929a133360246
- Full scan report link and password below:
Report link:
https://ca.secure.software/cityofcalgary/shareable-reports/hDcJ3QuXy6H-xgKX7KeW36bRvSlDFmif_IX9A9GfkKfdfXyowk-5JwwQB5HOfM_rg80NVn7hvfv_qQYOgm1c8udYXfV-E8P5MgP0hwpDWhi-pbsRVyn8YdllhmBwmk6jDJjmrxiYk5HMkDChflyiOIylcOCPAmAgHRY8xeRZy9w?fp=a0dbc0ec-8ec6-4d68-8402-bf3d5fe1332f
Password:
Y6tJSnjBI_2iSLEVi0QCEw
Please review the details and advise how we should address the highlighted issues.
Sincerely, Aaron
Original Message:
Sent: Aug 13, 2026 10:13 PM
From: Allan Solomon Mejia
Subject: VMware-workstation-full-17.6.4-24832109.exe Scan issues
Hello Aaron,
I compared the results for Workstation Pro 17.6.4 and the newer 26H1 scan. One important point is that neither report identifies a known vulnerability. Both show 0 vulnerabilities, with all 7 vulnerability policies passing.
The findings appear to be primarily related to signature/integrity and executable-format analysis, rather than confirmed CVEs. For 17.6.4, ReversingLabs reports two tampered signatures and three malware findings, including Win32.Certificate.Invalid, Win64.Certificate.Invalid, and Win64.Format.Malformed.
The 26H1 scan similarly reports two tampered signatures, but four malware findings: two Win64.Certificate.Invalid, one Win32.Format.Malformed, and one Win64.Format.Malformed.
Interestingly, upgrading therefore doesn't eliminate the scanner findings. The reports themselves also mention failed signature-integrity validation, package-integrity checks, malformed executable structures, and overlapping PE data/header structures.
That does not by itself establish that the VMware installer contains malware. Static-analysis tools can flag unusual executable packaging, signing, embedded components, or PE structures. However, the failed signature/integrity findings shouldn't simply be ignored either.
I would suggest:
- Confirm that both installers were downloaded directly from the official Broadcom/VMware download portal. Broadcom documents the current Workstation download process through its Support Portal.
- Compare the installer checksum against the checksum published for that download, if available.
- On Windows, check Properties → Digital Signatures → Details and confirm that Windows reports the signature as valid and inspect the signer/certificate chain.
- If the official Broadcom-downloaded binary still produces the ReversingLabs Certificate.Invalid / tampered-signature findings, provide Broadcom Support with the SHA-256 hash and these reports so they can determine whether this is expected packaging/signing behavior or something requiring remediation.
Broadcom's own documentation shows that signature-verification failures can have several causes, including trust/certificate issues, so I wouldn't classify these scan results as a confirmed VMware vulnerability or compromise without validating the actual affected files and signatures first.
Hope this helps clarify the scan results.