VMware ESXi
cpe:2.3:o:vmware:esxi:*:*:*:*:*:*:*, +2 more
- 8.0
- 7.0
A critical integer-overflow vulnerability has been identified in the VMXNET3 virtual network adapter used by VMware ESXi, Workstation, and Fusion. This vulnerability allows a malicious actor with local administrative privileges on a virtual machine to execute code on the host. The issue does not affect virtual adapters other than VMXNET3.
Exploitation of this vulnerability could lead to unauthorized code execution on the host machine.
Users can apply the patches available in the 'Fixed Version' column of the 'Response Matrix' found in the VMware Security Advisory VMSA-2025-0013. Additional guidance for updating VMware Tools asynchronously is also available in the FAQ section of the advisory.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.