
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-41237 is a VMCI (Virtual Machine Communication Interface) integer-underflow vulnerability in VMware ESXi, Workstation, and Fusion that leads to an out-of-bounds write, enabling potential VM escape and host-level code execution. It was disclosed on July 15, 2025, as part of Broadcom security advisory VMSA-2025-0013, and was originally discovered and exploited at the Pwn2Own Berlin 2025 competition. Affected versions include ESXi 7.0 (before ESXi70U3w-24784741), ESXi 8.0 (before ESXi80U3f-24784735 and ESXi80U2e-24789317), Workstation 17.x (before 17.6.4), and Fusion 13.x (before 13.6.4). The vulnerability carries a CVSS v3.1 base score of 9.3 (Critical) for Workstation/Fusion and 8.4 (Important) for ESXi (Broadcom Advisory, ZDI Advisory).
The root cause is an integer underflow (CWE-787: Out-of-bounds Write) in the VMCI subsystem, which is responsible for high-speed communication between virtual machines and the host. When a malicious actor triggers the underflow condition, it results in an out-of-bounds write that can corrupt memory in the VMX process — the host-side process managing the virtual machine. Exploitation requires local administrative privileges within the guest VM but does not require any user interaction or elevated host-side privileges. The vulnerability was reported by Corentin BAYET (@OnlyTheDuck) of REverse Tactics, working with the Zero Day Initiative at Pwn2Own Berlin 2025 (Broadcom Advisory, ZDI Advisory).
On VMware Workstation and Fusion, successful exploitation allows an attacker with guest VM administrative access to execute arbitrary code on the underlying host machine, representing a full VM escape with high confidentiality, integrity, and availability impact. On ESXi, exploitation is contained within the VMX sandbox, limiting the blast radius to the VMX process rather than the full hypervisor host. In both cases, the scope change (S:C in CVSS) reflects that the impact crosses the VM boundary, and in Workstation/Fusion environments this could enable lateral movement to the host OS and any other resources accessible from it (Broadcom Advisory, Security Affairs).
The vulnerability was demonstrated at Pwn2Own Berlin 2025, where researchers earned $340,000 for VMware-related exploits, confirming real-world exploitability under controlled conditions. A ZDI advisory was published on March 16, 2026, and Security Affairs reported it as exploited at Pwn2Own. No public proof-of-concept exploit code is known to be available outside the competition context, and there is no confirmed evidence of in-the-wild exploitation by threat actors. The EPSS score is approximately 0.017% (very low probability of exploitation in the next 30 days), and the vulnerability is not currently listed in the CISA KEV catalog (ZDI Advisory, Security Affairs, SecurityWeek).
vmware-vmx) on the host, particularly shells or network utilities not normally associated with VMware.vmware-vmx) on the host; VMware log files (e.g., vmware.log in the VM directory) showing VMCI-related errors, memory access violations, or unexpected process termination.Broadcom has released patches addressing CVE-2025-41237 with no available workarounds. Apply the following fixed versions immediately: ESXi 7.0 → ESXi70U3w-24784741; ESXi 8.0 → ESXi80U3f-24784735 or ESXi80U2e-24789317; VMware Workstation 17.x → 17.6.4; VMware Fusion 13.x → 13.6.4; VMware Cloud Foundation 5.x/4.5.x → async patch to the corresponding ESXi build. As an interim measure, restrict local administrative access within guest VMs and monitor for anomalous VMCI activity. Prioritize patching Workstation and Fusion deployments, as exploitation on those platforms can result in full host-level code execution rather than being sandboxed (Broadcom Advisory).
The vulnerability generated significant attention given its Pwn2Own Berlin 2025 origin, with SecurityWeek reporting that researchers earned $340,000 for VMware-related exploits at the event (SecurityWeek). BleepingComputer covered the patches as fixing "four ESXi zero-day bugs exploited at Pwn2Own Berlin," highlighting the severity of the VM escape class of vulnerabilities (BleepingComputer). Multiple national CERTs including CERT-EU, Canada's CCCS, Singapore's CSA, and Hong Kong's GovCERT issued advisories urging immediate patching. Reddit communities (r/vmware and r/sysadmin) saw active discussion with administrators expressing urgency around patching ESXi and Workstation deployments. Qualys and Tenable both released detection plugins shortly after the advisory was published (Qualys ThreatProtect).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."