Integer underflow in VMware ESXi - CVE-2025-41237

 

Integer underflow in VMware ESXi - CVE-2025-41237

Published: July 17, 2025


Vulnerability identifier: #VU113007
CSH Severity: Medium
CVSS v4: 5.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H]
CVE-ID: CVE-2025-41237
CWE-ID: CWE-191
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to compromise the affected host OS.

The vulnerability exists due to integer underflow in VMCI (Virtual Machine Communication Interface). A malicious guest with local administrative privileges on a virtual machine can trigger an integer underflow and execute arbitrary code as the virtual machine's VMX process running on the host.


Affected software

VMware ESXi
IBM Cloud Pak System
VMware Fusion
VMware Workstation
Cloud Foundation

How to mitigate CVE-2025-41237

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi80U2e-24789317, ESXi70U3w-24784741, ESXi80U3f-24784735
IBM Cloud Pak System - update to 2.3.6.1
VMware Fusion - update to 13.6.4
VMware Workstation - update to 17.6.4
Cloud Foundation - addressed in versions ESXi70U3w-24784741, ESXi80U3f-24784735

External References

Related Security Bulletins