cbcvebase.
CVE-2025-41236
published 2025-07-15

CVE-2025-41236: VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local…

PriorityP260critical9.3CVSS 3.1
AVLACLPRNUINSCCHIHAH
EPSS
2.17%
80.3th percentile
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

Affected

8 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation
vmwareesxi>= 7.0 < ESXi70U3w-24784741ESXi70U3w-24784741
vmwareesxi>= 8.0 < ESXi80U3f-24784735ESXi80U3f-24784735
vmwareesxi>= 8.0 < ESXi80U2e-24789317ESXi80U2e-24789317
vmwarefusion13.x – 13.6.4
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_platform
vmwareworkstation>= 17.x < 17.6.417.6.4

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-41236 is an integer-overflow vulnerability in the VMXNET3 virtual network adapter in VMware ESXi, Workstation, and Fusion. Only VMs configured with a VMXNET3 virtual network adapter are affected; non-VMXNET3 adapters are not impacted. Detection should focus on anomalous activity originating from guest VMs with VMXNET3 adapters targeting the host VMX process.
  • CVE-2025-41236 was exploited as a zero-day at Pwn2Own Berlin 2025 by Nguyen Hoang Thach of STARLabs SG, confirming real-world exploitability. Defenders should treat this as actively exploitable and prioritize patching or monitoring guest VMs with VMXNET3 adapters.
  • The vulnerability allows guest-to-host code execution (VM escape). Monitor for unexpected process spawning or privilege escalation from the VMX process on ESXi hosts, which could indicate exploitation of this flaw.
  • CVSS vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H indicates local access with no privileges required, no user interaction, and scope change to host. Audit all guest VMs for VMXNET3 adapter usage and restrict local administrative access within VMs as a compensating control.
  • ·Only VMs using the VMXNET3 virtual network adapter are vulnerable. VMs using other adapter types (e.g., E1000, VMXNET2) are not affected by CVE-2025-41236.
  • ·VMware has not provided any workarounds for this vulnerability; patching to the fixed software versions is the only remediation.
  • ·Exploitation requires local administrative privileges inside the guest VM. Remote exploitation is not possible.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.