#VU113008 Heap-based buffer overflow in VMware ESXi - CVE-2025-41238
Published: July 17, 2025
VMware ESXi
VMware, Inc
Description
The vulnerability allows an attacker to compromise the host OS.
The vulnerability exists due to a boundary error in the PVSCSI (Paravirtualized SCSI) controller. A malicious guest with local administrative privileges on a virtual machine can trigger a heap-based buffer overflow and execute arbitrary code as the virtual machine's VMX process running on the host.