CVE-2025-41239 is an information disclosure vulnerability in VMware ESXi, Workstation, Fusion, and VMware Tools, stemming from uninitialized memory in vSockets. An attacker with local administrative privileges on a virtual machine could exploit this to leak memory from processes using vSockets. This vulnerability has a CVSS score of 7.1 (HIGH), indicating a local attack vector with low complexity, requiring no user interaction, and resulting in high confidentiality impact. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, including reports of it being exploited as a zero-day at Pwn2Own Berlin.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| VMware | Tools | >= 12.x.x, 11.x.x,, < 12.5.3, >= 13.x.x, < 13.0.1.0CNA affecteddefault unaffected | |
| VMware | Cloud Foundation | 5.x, 4.5.xCNA affecteddefault unaffected | |
| VMware | ESXi | >= 7.0, < ESXi70U3w-24784741, >= 8.0, < ESXi80U2e-24789317, >= 8.0, < ESXi80U3f-24784735CNA affecteddefault unaffected | |
| VMware | Fusion | >= 13.x, < 13.6.4CNA affecteddefault unaffected | |
| VMware | Telco Cloud Infrastructure | 3.x, 2.xCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.