
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-41236 is a critical integer-overflow vulnerability in the VMXNET3 virtual network adapter affecting VMware ESXi, Workstation, and Fusion. Disclosed on July 15, 2025, as part of Broadcom security advisory VMSA-2025-0013, it was discovered and reported by Nguyen Hoang Thach (@hi_im_d4rkn3ss) of STARLabs SG during the Pwn2Own Berlin 2025 competition. Affected versions include ESXi 7.0 (before ESXi70U3w-24784741), ESXi 8.0 (before ESXi80U3f-24784735 and ESXi80U2e-24789317), Workstation 17.x (before 17.6.4), and Fusion 13.x (before 13.6.4); non-VMXNET3 virtual adapters are not affected. It carries a CVSS v3.1 base score of 9.3 (Critical) (Broadcom Advisory, ZDI Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), triggered by an integer overflow in the VMXNET3 virtual network adapter's processing logic within VMware's hypervisor stack. An integer overflow condition causes a subsequent out-of-bounds write, which can be leveraged to corrupt memory in the host's VMX process. The attack vector is local, requiring an attacker to have local administrative privileges inside a guest virtual machine configured with a VMXNET3 adapter — no user interaction or network access is required. The vulnerability was demonstrated at Pwn2Own Berlin 2025, confirming practical exploitability in a controlled environment (Broadcom Advisory, ZDI Advisory).
Successful exploitation allows a malicious actor with local administrative privileges inside a guest VM to execute arbitrary code on the underlying host system, achieving a full virtual machine escape. This results in high impact to confidentiality, integrity, and availability of the host, with a changed scope (S:C) indicating that the compromise extends beyond the guest VM boundary. An attacker who escapes the VM could potentially pivot to other VMs on the same host, access sensitive host-level data, or disrupt hypervisor operations across the entire virtualization infrastructure (Broadcom Advisory, Qualys ThreatProtect).
The vulnerability was exploited live at Pwn2Own Berlin 2025, confirming real-world exploitability, though no public proof-of-concept exploit code has been released as of the time of reporting. The Zero Day Initiative published an advisory (ZDI-26-189) in March 2026 following the standard disclosure timeline. No evidence of in-the-wild exploitation outside of the competition context has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017%, reflecting low but non-zero probability of near-term exploitation (ZDI Advisory, Broadcom Advisory). Shadowserver reported approximately 17,000 VMware ESXi servers remained unpatched weeks after disclosure, highlighting significant exposure (SecurityWeek).
/var/log/vmkernel.log or vmware.log within the VM's working directory; memory fault or segmentation fault entries associated with VMXNET3 device emulation./tmp or /scratch directories created around the time of suspicious guest activity.Broadcom has released patches addressing CVE-2025-41236 with no available workarounds — patching is the only remediation. Apply the following fixed versions: ESXi 8.0 → ESXi80U3f-24784735 or ESXi80U2e-24789317; ESXi 7.0 → ESXi70U3w-24784741; Workstation 17.x → 17.6.4; Fusion 13.x → 13.6.4; Cloud Foundation 5.x → async patch to ESXi80U3f-24784735; Cloud Foundation 4.5.x → async patch to ESXi70U3w-24784741. As an interim measure where patching is not immediately possible, consider restricting local administrative access to guest VMs, implementing network segmentation, and temporarily replacing VMXNET3 adapters with non-affected adapter types (Broadcom Advisory).
The vulnerability received significant attention given its Pwn2Own Berlin 2025 origin, with researchers earning $340,000 in prizes for VMware-related exploits at the event (SecurityWeek). BleepingComputer and SecurityAffairs covered the patches as part of a broader story on four ESXi zero-days fixed simultaneously (BleepingComputer). Multiple national CERTs — including Canada (CCCS), Singapore (CSA), Hong Kong (GovCERT), Belgium (CCB), and ENISA/CERT-EU — issued advisories urging immediate patching. Heise.de reported weeks after disclosure that administrators were failing to apply the critical patches, with Shadowserver identifying approximately 17,000 still-vulnerable ESXi servers publicly exposed (Heise). Reddit communities (r/vmware, r/sysadmin) actively discussed the advisory with urgency.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."