cbcvebase.
CVE-2025-41236
published 2025-07-15

CVE-2025-41236: VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local…

critical9.3CVSS 3.1
AVLACLPRNUINSCCHIHAH
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

Affected

8 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation
vmwareesxi>= 7.0 < ESXi70U3w-24784741ESXi70U3w-24784741
vmwareesxi>= 8.0 < ESXi80U3f-24784735ESXi80U3f-24784735
vmwareesxi>= 8.0 < ESXi80U2e-24789317ESXi80U2e-24789317
vmwarefusion13.x – 13.6.4
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_platform
vmwareworkstation>= 17.x < 17.6.417.6.4