Heap-based buffer overflow in VMware ESXi - CVE-2025-41238
Published: July 17, 2025
VMware ESXi
Detailed vulnerability description
The vulnerability allows an attacker to compromise the host OS.
The vulnerability exists due to a boundary error in the PVSCSI (Paravirtualized SCSI) controller. A malicious guest with local administrative privileges on a virtual machine can trigger a heap-based buffer overflow and execute arbitrary code as the virtual machine's VMX process running on the host.