CyberzSOC

Publication detail
← Back to advisories & guidance

2025-026: Critical Vulnerabilities in VMWare Products ↗ source

July 18, 2025 CERT-EU Advisory

Summary

It is recommended updating affected products as soon as possible, prioritising the ones hosting virtual machines that are Internet facing. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue. The vulnerability CVE-2025-41237, with a CVSS score of 9.3, is an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-41236 9.3 Critical VMware ESXi VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local a…
CVE-2025-41237 9.3 Critical VMware Cloud Foundation VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds wr…
CVE-2025-41238 9.3 Critical VMware ESXi VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bo…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.