ZDI-CAN-27157: ZDI-26-189: (Pwn2Own) VMware ESXi VMXNET3 Integer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2025-41236.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27157?
The severity of ZDI-CAN-27157 is classified as high due to its potential to allow local privilege escalation.
How do I fix ZDI-CAN-27157?
To mitigate ZDI-CAN-27157, users should apply the latest security patches provided by VMware for ESXi.
Which versions of VMware ESXi are affected by ZDI-CAN-27157?
ZDI-CAN-27157 affects various versions of VMware ESXi that are not patched against this vulnerability.
What type of attack is described by ZDI-CAN-27157?
ZDI-CAN-27157 describes a local privilege escalation attack that can be exploited by an attacker with high-privileged code execution.
Can ZDI-CAN-27157 be exploited remotely?
No, ZDI-CAN-27157 requires an attacker to have local access to the vulnerable VMware ESXi installation.