CVE-2025-41237General

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-16); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-16: 1Mentions · 2026-03-18: 1Mentions · 2026-08-10: 1Technical Details · 2026-03-16: 1Technical Details · 2026-08-10: 103-1603-1808-10
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-161
Disclosure1
2026-03-181
General1
2026-08-101
General1
Full discourse3 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-188|CVE-2025-41237] (Pwn2Own) VMware ESXi VMCI Integer Underflow Local Privilege Escalation Vulnerability (CVSS 8.2; Credit: Corentin "@OnlyTheDuck" BAYET from REverse Tactics) https://www.zerodayinitiative.com/advisories/ZDI-26-188/

    Post summary

    The ZeroDay Initiative advisory discloses a VMware ESXi VMCI integer underflow flaw that enables local privilege escalation, provides its CVSS score, but does not supply a PoC, exploit, active exploitation hints, or patch information.

    0402081.6K
    5.4K followersView on X
  • Arlis@YellowSnowman23
    General

    @colere_0 @stef4n24 @SusgIRL446 @v12sec VM Escapes labeled as an RCE. Keep taking the L faggot https://www.sentinelone.com/vulnerability-database/cve-2025-41237/ https://www.sentinelone.com/vulnerability-database/cve-2021-3929/

    Post summary

    The tweet references two CVE entries and labels one as an RCE, but provides no actionable details, PoC, exploit, or mitigation information.

    10060101
    9 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-3342 2 - CVE-2026-4149 3 - CVE-2026-32635 4 - CVE-2025-41237 5 - CVE-2019-17571 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists trending CVEs and links to a dashboard, providing no technical or actionable details.

    00010169
    1.7K followersView on X

Explore more