Integer overflow in VMware ESXi - CVE-2025-41236

 

Integer overflow in VMware ESXi - CVE-2025-41236

Published: July 17, 2025


Vulnerability identifier: #VU113006
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-41236
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to compromise the host OS.

The vulnerability exists due to integer overflow in the VMXNET3 virtual network adapter. A malicious guest with administrative privileges can trigger an integer overflow and execute arbitrary code on the host OS.


Affected software

VMware ESXi
IBM Cloud Pak System
VMware Fusion
VMware Workstation
Cloud Foundation

How to mitigate CVE-2025-41236

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi80U2e-24789317, ESXi70U3w-24784741, ESXi80U3f-24784735
IBM Cloud Pak System - update to 2.3.6.1
VMware Fusion - update to 13.6.4
VMware Workstation - update to 17.6.4
Cloud Foundation - addressed in versions ESXi70U3w-24784741, ESXi80U3f-24784735

External References

Related Security Bulletins