PT-2025-29584 · Vmware · Vmware Esxi +2
Published
2025-07-15
·
Updated
2025-08-01
·
CVE-2025-41236
9.3
Critical
Base vector | Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
VMware ESXi, Workstation, and Fusion versions (affected versions not specified)
Description:
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with a VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non-VMXNET3 virtual adapters are not affected. The vulnerability is related to a buffer overflow in the VMXNET3 virtual network adapter. Exploitation could allow an attacker to execute arbitrary code.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Memory Corruption
Weakness Enumeration
Related Identifiers
Affected Products
References · 23
- https://bdu.fstec.ru/vul/2025-08590 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-41236 · Security Note
- https://t.me/cvenotify/129087 · Telegram Post
- https://reddit.com/r/vmware/comments/1m0m45t/vmsa20250013_new_vmware_critical_security_advisory · Reddit Post
- https://reddit.com/r/sysadmin/comments/1m0wts6/heads_up_new_vmware_critical_security_advisory · Reddit Post
- https://twitter.com/The_Cyber_News/status/1945409861640163377 · Twitter Post
- https://twitter.com/VirtualG_UK/status/1946320088577069513 · Twitter Post
- https://twitter.com/ZeroDayFacts/status/1947234345002955018 · Twitter Post
- https://twitter.com/catnap707/status/1945985411970679182 · Twitter Post
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877 · Note
- https://twitter.com/TweetThreatNews/status/1945803852453662739 · Twitter Post
- https://twitter.com/CVEnew/status/1945195278140592164 · Twitter Post
- https://twitter.com/ripjyr/status/1946468754780778576 · Twitter Post
- https://twitter.com/RobotRalf_/status/1948137889931673887 · Twitter Post
- https://twitter.com/ripjyr/status/1946468987224858858 · Twitter Post