CVE-2025-41236CRITICAL 9.3EPSS p79.3%

CVE-2025-41236CVE-2025-41236

Description

VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

Scoring

CVSS 3.19.3 (CRITICAL)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS2.11% probability of exploitation · percentile 79.3% · 2026-06-19T12:03:05Z
Published2025-07-15
Last modified2026-04-15

Underlying weaknesses· 1

CWE-787

References

  1. https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877

1

TypeTargetConfidenceTier
WeaknessOut-of-bounds Writecwe-7870%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-41237
CVE
CVE-2025-41238
CVE
VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability
CVE
VMware ESXi Arbitrary Write Vulnerability
CVE
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
CVE
VMware vCenter Server Privilege Escalation Vulnerability
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.