cbcvebase.
CVE-2025-41239
published 2025-07-15

CVE-2025-41239: VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A…

PriorityP334high7.1CVSS 3.1
AVLACLPRNUINSCCHINAN
EPSS
2.15%
80.1th percentile
VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets.

Affected

10 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation
vmwareesxi>= 7.0 < ESXi70U3w-24784741ESXi70U3w-24784741
vmwareesxi>= 8.0 < ESXi80U3f-24784735ESXi80U3f-24784735
vmwareesxi>= 8.0 < ESXi80U2e-24789317ESXi80U2e-24789317
vmwarefusion>= 13.x < 13.6.413.6.4
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_platform
vmwaretools>= 12.x.x, 11.x.x, < 12.5.312.5.3
vmwaretools>= 13.x.x < 13.0.1.013.0.1.0
vmwareworkstation>= 17.x < 17.6.417.6.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.