Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-41239

20
FAUCET Score

CVE-2025-41239 is an information disclosure vulnerability in VMware ESXi, Workstation, Fusion, and VMware Tools, stemming from uninitialized memory in vSockets. An attacker with local administrative privileges on a virtual machine could exploit this to leak memory from processes using vSockets. This vulnerability has a CVSS score of 7.1 (HIGH), indicating a local attack vector with low complexity, requiring no user interaction, and resulting in high confidentiality impact. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, including reports of it being exploited as a zero-day at Pwn2Own Berlin.

Impacted Technologies

VendorProductVersion(s)CPE
VMwareTools
>= 12.x.x, 11.x.x,, < 12.5.3, >= 13.x.x, < 13.0.1.0CNA affecteddefault unaffected
VMwareCloud Foundation
5.x, 4.5.xCNA affecteddefault unaffected
VMwareESXi
>= 7.0, < ESXi70U3w-24784741, >= 8.0, < ESXi80U2e-24789317, >= 8.0, < ESXi80U3f-24784735CNA affecteddefault unaffected
VMwareFusion
>= 13.x, < 13.6.4CNA affecteddefault unaffected
VMwareTelco Cloud Infrastructure
3.x, 2.xCNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.5
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.15%
Probability of exploitation in next 30 days
EPSS Percentile
80.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0215 is in the 94th percentile among its peer group of 3,241 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

feathersjspatch availablevia llm_extracted
Fixed in: ESXi 7.0U3w or ESXi 8.0U3f or greater
View patch
sophospatch availablevia llm_extracted
Fixed in: ESXi 7.0U3w or ESXi 8.0U3f or greater
View patch

Vendor Advisories (2)

sophosllm-sophos-75ce555a0588dd2dCRITICAL

Multiple vulnerabilities in VMware ESXi

Jul 15, 2025
feathersjsllm-feathersjs-3d64414f41ba1ba8CRITICAL

Multiple vulnerabilities in VMware ESXi (VMSA-2025-0013)

References

support.broadcom.com / web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877