CVE-2025-41239
BaseFortify
Publication date: 2025-07-15
Last updated on: 2025-07-15
Assigner: VMware
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| vmware | workstation | 3.1 |
| vmware | esxi | 3.1 |
| vmware | tools | 3.1 |
| vmware | fusion | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-908 | The product uses or accesses a resource that has not been initialized. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an information disclosure issue in VMware ESXi, Workstation, Fusion, and VMware Tools caused by the use of uninitialized memory in vSockets. A malicious actor with local administrative privileges on a virtual machine could exploit this to leak memory from processes communicating via vSockets.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of sensitive information by leaking memory contents from processes communicating through vSockets. This could expose confidential data to a malicious actor who has local administrative access to a virtual machine.