CVE-2025-41236
BaseFortify
Publication date: 2025-07-15
Last updated on: 2025-07-15
Assigner: VMware
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| vmware | vmxnet3 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an integer-overflow issue in the VMXNET3 virtual network adapter used by VMware ESXi, Workstation, and Fusion. A malicious actor who has local administrative privileges on a virtual machine with the VMXNET3 adapter can exploit this flaw to execute code on the host system. Other virtual network adapters are not affected.
How can this vulnerability impact me? :
If exploited, this vulnerability allows an attacker with local admin access on a VM to execute code on the host machine, potentially compromising the host system's security, leading to unauthorized control, data breaches, or disruption of services.