CVE-2025-25058: Low severity VMware ESXi vulnerability
Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25058?
CVE-2025-25058 is considered a moderate severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2025-25058?
To remediate CVE-2025-25058, update the ESXi kernel mode driver to versions 2.2.2.0 for ESXi 8.0 and 2.2.3.0 for ESXi 9.0 or later.
Who is affected by CVE-2025-25058?
CVE-2025-25058 affects users of VMware ESXi with the Intel Ethernet 800-Series driver versions prior to 2.2.2.0 and 2.2.3.0.
What causes CVE-2025-25058?
CVE-2025-25058 is caused by improper initialization in the ESXi kernel mode driver for Intel Ethernet devices.
Can CVE-2025-25058 be exploited remotely?
CVE-2025-25058 requires authenticated access, so exploitation necessitates an attacker to be logged in to the affected system.