PT-2026-40526 · Vmware · Vmware Esxi

Published

2026-05-12

·

Updated

2026-05-13

·

CVE-2025-62627

CVSS v4.0

7.2

High

VectorAV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H
Name of the Vulnerable Software and Affected Versions VMWare ESXi (affected versions not specified)
Description An untrusted pointer dereference in the ionic cloud driver allows an attacker with an unprivileged VM to read kernel memory or memory from co-located guest VMs. This issue could lead to a loss of confidentiality or availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62627

Affected Products

Vmware Esxi