Input validation error in VMware ESXi - CVE-2025-41226
Published: May 20, 2025
Vulnerability identifier: #VU109485
CSH Severity: Medium
CVSS v4: 6.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H]
CVE-ID: CVE-2025-41226
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote guest to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote guest can perform a denial of service attack against other guest VMs with VMware Tools running and guest operations enabled.
Affected software
VMware ESXi
IBM Cloud Pak System
IBM Cloud Pak System
How to mitigate CVE-2025-41226
Install updates from vendor's website.
VMware ESXi - addressed in versions ESXi70U3sv-24723868, ESXi80U3e-24659227
IBM Cloud Pak System - update to 2.3.6.1
IBM Cloud Pak System - update to 2.3.6.1