CVE-2025-41236: VMXNET3 integer-overflow vulnerability
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41236?
CVE-2025-41236 has been rated as a critical severity vulnerability due to its potential to allow code execution on the host.
How do I fix CVE-2025-41236?
To fix CVE-2025-41236, apply the latest security patches provided by VMware for ESXi, Workstation, and Fusion.
Who is affected by CVE-2025-41236?
CVE-2025-41236 affects VMware ESXi, Workstation, and Fusion users with the VMXNET3 virtual network adapter.
What type of vulnerability is CVE-2025-41236?
CVE-2025-41236 is classified as an integer overflow vulnerability.
Can CVE-2025-41236 be exploited remotely?
CVE-2025-41236 cannot be exploited remotely as it requires local administrative privileges on the virtual machine.