CVE-2025-41226: Guest Operations Denial-of-Service Vulnerability
VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools running and guest operations enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41226?
CVE-2025-41226 has been categorized as a denial-of-service vulnerability affecting VMware ESXi.
How do I fix CVE-2025-41226?
To fix CVE-2025-41226, you should apply the latest security patches provided by VMware for ESXi.
Who is affected by CVE-2025-41226?
CVE-2025-41226 affects any VMware ESXi installations where a malicious actor has guest operation privileges.
What are the potential impacts of CVE-2025-41226?
The potential impact of CVE-2025-41226 is a denial-of-service condition on affected VMware ESXi systems.
Is user authentication required to exploit CVE-2025-41226?
Yes, a malicious actor must already be authenticated through vCenter Server or ESXi to exploit CVE-2025-41226.