Heap-based buffer overflow in VMware ESXi - CVE-2025-41238
Published: July 17, 2025
Vulnerability details
The vulnerability allows an attacker to compromise the host OS.
The vulnerability exists due to a boundary error in the PVSCSI (Paravirtualized SCSI) controller. A malicious guest with local administrative privileges on a virtual machine can trigger a heap-based buffer overflow and execute arbitrary code as the virtual machine's VMX process running on the host.
Affected software
IBM Cloud Pak System
VMware Fusion
VMware Workstation
Cloud Foundation
How to mitigate CVE-2025-41238
IBM Cloud Pak System - update to 2.3.6.1
VMware Fusion - update to 13.6.4
VMware Workstation - update to 17.6.4
Cloud Foundation - addressed in versions ESXi70U3w-24784741, ESXi80U3f-24784735