CVE-2025-62627: High severity VMware ESXi vulnerability
An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62627?
CVE-2025-62627 is considered to have a high severity due to the potential for unauthorized access to sensitive memory.
How do I fix CVE-2025-62627?
To fix CVE-2025-62627, ensure you are running the latest patched version of VMware ESXi as provided by VMware.
What type of vulnerability is CVE-2025-62627?
CVE-2025-62627 is an untrusted pointer dereference vulnerability affecting the ionic cloud driver in VMware ESXi.
Who can exploit CVE-2025-62627?
An attacker with an unprivileged VM can exploit CVE-2025-62627 to gain access to sensitive memory.
What are the potential impacts of CVE-2025-62627?
The potential impacts of CVE-2025-62627 include loss of confidentiality or availability of kernel and guest VM memory.