VMware fixed four vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools that were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025. Three of the patched flaws have a severity rating of 9.3, as they allow programs running in a guest virtual machine to execute commands on the host. These flaws are tracked as CVE-2025-41236, CVE-2025-41237, and CVE-2025-41238. These flaws are described in the security advisory as: The fourth flaw, tracked as CVE-2025-41239, received a 7.1 rating as it is an information disclosure. It was also discovered by Corentin BAYET of REverse Tactics, who chained with CVE-2025-41237 during the hacking contest. VMware has not provided any workarounds, and the only way to fix these vulnerabilities is to install the new versions of the software. It should be noted that CVE-2025-41239 impacts VMware Tools for Windows, which requires a different upgrade process. These vulnerabilities were demonstrated as zero-days during the Pwn2Own Berlin 2025 hacking contest, where security researchers collected $1,078,750 after exploiting 29 zero-day vulnerabilities. CISOs know that getting board buy-in starts with a clear, strategic view of how cloud security drives business value. This free, editable board report deck helps security leaders present risk, impact, and priorities in clear business terms. Turn security updates into meaningful conversations and faster decision-making in the boardroom. Ruckus Networks leaves severe flaw...
VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin
BleepingComputer
·Lawrence Abrams
·Published Jul 17, 2025
·Updated
Affected Software
4 affected components
VMware ESXi
VMware Workstation
VMware Fusion
VMware Tools=Windows
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the fixing of four zero-day vulnerabilities in VMware products, including ESXi, Workstation, Fusion, and Tools, which were exploited during the Pwn2Own Berlin 2025 event.
2
What security implications are discussed?
The vulnerabilities posed significant risks, with three of them having a high severity rating of 9.3, indicating they could be easily exploited by attackers.
3
What products or software are affected?
The affected products include VMware ESXi, VMware Workstation, VMware Fusion, and VMware Tools.
4
When did the zero-day exploits occur?
The zero-day exploits were demonstrated at the Pwn2Own Berlin hacking contest held in May 2025.
5
What actions has VMware taken in response to these vulnerabilities?
VMware has released patches to address the four vulnerabilities and protect users from potential exploits.