CVE-2025-41236
published 2025-07-15CVE-2025-41236: VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local…
PriorityP260critical9.3CVSS 3.1
AVLACLPRNUINSCCHIHAH
EPSS
2.17%
80.3th percentile
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | — | — |
| vmware | esxi | >= 7.0 < ESXi70U3w-24784741 | ESXi70U3w-24784741 |
| vmware | esxi | >= 8.0 < ESXi80U3f-24784735 | ESXi80U3f-24784735 |
| vmware | esxi | >= 8.0 < ESXi80U2e-24789317 | ESXi80U2e-24789317 |
| vmware | fusion | 13.x – 13.6.4 | — |
| vmware | telco_cloud_infrastructure | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | workstation | >= 17.x < 17.6.4 | 17.6.4 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-41236 is an integer-overflow vulnerability in the VMXNET3 virtual network adapter in VMware ESXi, Workstation, and Fusion. Only VMs configured with a VMXNET3 virtual network adapter are affected; non-VMXNET3 adapters are not impacted. Detection should focus on anomalous activity originating from guest VMs with VMXNET3 adapters targeting the host VMX process. ↗
- →CVE-2025-41236 was exploited as a zero-day at Pwn2Own Berlin 2025 by Nguyen Hoang Thach of STARLabs SG, confirming real-world exploitability. Defenders should treat this as actively exploitable and prioritize patching or monitoring guest VMs with VMXNET3 adapters. ↗
- →The vulnerability allows guest-to-host code execution (VM escape). Monitor for unexpected process spawning or privilege escalation from the VMX process on ESXi hosts, which could indicate exploitation of this flaw. ↗
- →CVSS vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H indicates local access with no privileges required, no user interaction, and scope change to host. Audit all guest VMs for VMXNET3 adapter usage and restrict local administrative access within VMs as a compensating control. ↗
- ·Only VMs using the VMXNET3 virtual network adapter are vulnerable. VMs using other adapter types (e.g., E1000, VMXNET2) are not affected by CVE-2025-41236. ↗
- ·VMware has not provided any workarounds for this vulnerability; patching to the fixed software versions is the only remediation. ↗
- ·Exploitation requires local administrative privileges inside the guest VM. Remote exploitation is not possible. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Lifecycle Services with VMware
cisa_ics·2025-07-31·CVSS 9.3
[CRITICAL] Rockwell Automation Lifecycle Services with VMware
ICS Advisory
##
Rockwell Automation Lifecycle Services with VMware
Release DateJuly 31, 2025
Alert CodeICSA-25-212-02
Related topics:
Industrial Control Systems, Industrial Control System Vulnerabilities
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Low attack complexity
- Vendor: Rockwell Automation
- Equipment: Lifecycle Services with VMware
- Vulnerabilities: Out-of-bounds Write, Use of Uninitialized Resource
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could lead to code execution on the host or leakage of memory from processes communicating with vSockets.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Rockwell Automation reports the following Lifecycle Services with VMware are affected:
- Industrial Da
GHSA
GHSA-vvjv-89cj-78fr: VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter
ghsa_unreviewed·2025-07-15
CVE-2025-41236 [CRITICAL] CWE-787 GHSA-vvjv-89cj-78fr: VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
No detection rules found.
No public exploits indexed.
Checkpoint
21st July – Threat Intelligence Report
blogs_checkpoint·2025-07-21
CVE-2025-53770 21st July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 21st July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st July, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Luxury retailer Louis Vuitton has suffered a cyber-attack that resulted in the exfiltration of certain personal data of customers from the UK, South Korea, Turkey , Italy, and Sweden after unauthorized access to its systems. No payment information was compromised, but sensitive client data was exposed, reportedly due to a breac
Bleepingcomputer
VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin
blogs_bleepingcomputer·2025-07-17·CVSS 9.3
CVE-2025-41236 [CRITICAL] VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin
## VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin
## Lawrence Abrams
VMware fixed four vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools that were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025.
Three of the patched flaws have a severity rating of 9.3, as they allow programs running in a guest virtual machine to execute commands on the host. These flaws are tracked as CVE-2025-41236, CVE-2025-41237, and CVE-2025-41238.
These flaws are described in the security advisory as:
CVE-2025-41236 : VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. Nguyen Hoang Thach of STARLabs SG used this flaw at Pwn2Own.
CVE-2025-41237 : VMware ESXi, Workstation, and Fusion
2025-07-15
Published