
[ZDI-26-188|CVE-2025-41237] (Pwn2Own) VMware ESXi VMCI Integer Underflow Local Privilege Escalation Vulnerability (CVSS 8.2; Credit: Corentin "@OnlyTheDuck" BAYET from REverse Tactics) https://www.zerodayinitiative.com/advisories/ZDI-26-188/
Post summary
The ZeroDay Initiative advisory discloses a VMware ESXi VMCI integer underflow flaw that enables local privilege escalation, provides its CVSS score, but does not supply a PoC, exploit, active exploitation hints, or patch information.


