Integer overflow in VMware ESXi - CVE-2025-41236
Published: July 17, 2025
Vulnerability identifier: #VU113006
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-41236
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to compromise the host OS.
The vulnerability exists due to integer overflow in the VMXNET3 virtual network adapter. A malicious guest with administrative privileges can trigger an integer overflow and execute arbitrary code on the host OS.
Affected software
VMware ESXi
IBM Cloud Pak System
VMware Fusion
VMware Workstation
Cloud Foundation
IBM Cloud Pak System
VMware Fusion
VMware Workstation
Cloud Foundation
How to mitigate CVE-2025-41236
Install updates from vendor's website.
VMware ESXi - addressed in versions ESXi80U2e-24789317, ESXi70U3w-24784741, ESXi80U3f-24784735
IBM Cloud Pak System - update to 2.3.6.1
VMware Fusion - update to 13.6.4
VMware Workstation - update to 17.6.4
Cloud Foundation - addressed in versions ESXi70U3w-24784741, ESXi80U3f-24784735
IBM Cloud Pak System - update to 2.3.6.1
VMware Fusion - update to 13.6.4
VMware Workstation - update to 17.6.4
Cloud Foundation - addressed in versions ESXi70U3w-24784741, ESXi80U3f-24784735