CVE-2025-41239
published 2025-07-15CVE-2025-41239: VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A…
PriorityP334high7.1CVSS 3.1
AVLACLPRNUINSCCHINAN
EPSS
2.15%
80.1th percentile
VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | — | — |
| vmware | esxi | >= 7.0 < ESXi70U3w-24784741 | ESXi70U3w-24784741 |
| vmware | esxi | >= 8.0 < ESXi80U3f-24784735 | ESXi80U3f-24784735 |
| vmware | esxi | >= 8.0 < ESXi80U2e-24789317 | ESXi80U2e-24789317 |
| vmware | fusion | >= 13.x < 13.6.4 | 13.6.4 |
| vmware | telco_cloud_infrastructure | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | tools | >= 12.x.x, 11.x.x, < 12.5.3 | 12.5.3 |
| vmware | tools | >= 13.x.x < 13.0.1.0 | 13.0.1.0 |
| vmware | workstation | >= 17.x < 17.6.4 | 17.6.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Lifecycle Services with VMware
cisa_ics·2025-07-31·CVSS 9.3
[CRITICAL] Rockwell Automation Lifecycle Services with VMware
ICS Advisory
##
Rockwell Automation Lifecycle Services with VMware
Release DateJuly 31, 2025
Alert CodeICSA-25-212-02
Related topics:
Industrial Control Systems, Industrial Control System Vulnerabilities
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Low attack complexity
- Vendor: Rockwell Automation
- Equipment: Lifecycle Services with VMware
- Vulnerabilities: Out-of-bounds Write, Use of Uninitialized Resource
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could lead to code execution on the host or leakage of memory from processes communicating with vSockets.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Rockwell Automation reports the following Lifecycle Services with VMware are affected:
- Industrial Da
GHSA
GHSA-8p72-rxh7-qv97: VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSo
ghsa_unreviewed·2025-07-15
CVE-2025-41239 [HIGH] CWE-908 GHSA-8p72-rxh7-qv97: VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSo
VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets.
No detection rules found.
No public exploits indexed.
Checkpoint
21st July – Threat Intelligence Report
blogs_checkpoint·2025-07-21
CVE-2025-53770 21st July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 21st July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st July, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Luxury retailer Louis Vuitton has suffered a cyber-attack that resulted in the exfiltration of certain personal data of customers from the UK, South Korea, Turkey , Italy, and Sweden after unauthorized access to its systems. No payment information was compromised, but sensitive client data was exposed, reportedly due to a breac
Bleepingcomputer
VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin
blogs_bleepingcomputer·2025-07-17·CVSS 9.3
CVE-2025-41236 [CRITICAL] VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin
## VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin
## Lawrence Abrams
VMware fixed four vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools that were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025.
Three of the patched flaws have a severity rating of 9.3, as they allow programs running in a guest virtual machine to execute commands on the host. These flaws are tracked as CVE-2025-41236, CVE-2025-41237, and CVE-2025-41238.
These flaws are described in the security advisory as:
CVE-2025-41236 : VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. Nguyen Hoang Thach of STARLabs SG used this flaw at Pwn2Own.
CVE-2025-41237 : VMware ESXi, Workstation, and Fusion
2025-07-15
Published