#VU113007 Integer underflow in VMware ESXi - CVE-2025-41237
Published: July 17, 2025
VMware ESXi
VMware, Inc
Description
The vulnerability allows an attacker to compromise the affected host OS.
The vulnerability exists due to integer underflow in VMCI (Virtual Machine Communication Interface). A malicious guest with local administrative privileges on a virtual machine can trigger an integer underflow and execute arbitrary code as the virtual machine's VMX process running on the host.