CVE-2025-41229: VMware Cloud Foundation Directory Traversal Vulnerability
Published May 20, 2025
·Updated
VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to access certain internal services.
Affected Software
1 affected component
VMware Cloud Foundation
Event History
May 20, 2025
CVE Published
via MITRE·12:53 PM
Data Sourced
via MITRE·12:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-41229?
The severity of CVE-2025-41229 is considered critical due to the potential for unauthorized access to internal services.
2
How do I fix CVE-2025-41229?
To fix CVE-2025-41229, apply the latest security patches provided by VMware for Cloud Foundation.
3
Who is affected by CVE-2025-41229?
Organizations using VMware Cloud Foundation with network access to port 443 are vulnerable to CVE-2025-41229.
4
What type of vulnerability is CVE-2025-41229?
CVE-2025-41229 is a directory traversal vulnerability that allows attackers to bypass access controls.
5
Can CVE-2025-41229 be exploited remotely?
Yes, CVE-2025-41229 can be exploited by malicious actors with network access to the affected port.