Broadcom patches critical VMware flaws exploited at Pwn2Own Berlin 2025
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-41236 | VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue. NVD description · AI analysis pending | 9.3 | 2% | — | — | ||
| CVE-2025-41237 | VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed. NVD description · AI analysis pending | 9.3 | <1% | — | — | ||
| CVE-2025-41238 | VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox and exploitable only with configurations that are unsupported. On Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed. NVD description · AI analysis pending | 9.3 | <1% | — | — | ||
| CVE-2025-41239 | VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets. NVD description · AI analysis pending | 7.1 | 3% | — | — |
Full article256 words · extracted from securityaffairs.com · click to collapse

VMware patched flaws disclosed during the Pwn2Own Berlin 2025 hacking contest, where researchers earned $340,000 for exploiting them.
Broadcom four vulnerabilities in VMware products demonstrated at Pwn2Own Berlin 2025. White hat hackers earned over $340,000 for VMware exploits, including $150,000 awarded to STARLabs SG for using an integer overflow flaw to compromise VMware ESXi.
Below are the descriptions of the vulnerabilities:
- CVE-2025-41236 (CVSS score of 9.3) is an integer overflow in the VMXNET3 adapter used by STARLabs SG. The flaw could let attackers with admin access on a VM run code on the host. STARLabs SG demonstrated this flaw at Pwn2Own and earned $150,000.
- CVE-2025-41237 (CVSS score of 9.3) is an integer underflow in VMCI exploited by REverse Tactics;
- CVE-2025-41238 (CVSS score of 9.3) is a heap overflow in the PVSCSI controller leveraged by Synacktiv. Synacktiv earned $80,000 at Pwn2Own for exploiting CVE-2025-41238, a critical VMware Workstation flaw that lets a local VM admin execute code on the host.
- CVE-2025-41239 (CVSS score of 7.1) is an information disclosure flaw discovered by Corentin BAYET of REverse Tactics and was chained with CVE-2025-41237 at Pwn2Own. A researcher from Theori also independently discovered CVE-2025-41239.
The REverse Tactics team earned $112,500 for an ESXi exploit using the bugs CVE-2025-41237 and CVE-2025-41239.
Broadcom is not aware of attacks in the wild exploiting these vulnerabilities.
“Broadcom has no information to suggest that exploitation of these issues has occurred in the wild.” states the company.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/180062/security/broadcom-patches-critical-vmware-flaws-exploited-at-pwn2own-berlin-2025.html