Denial-of-Service Vulnerability in VMware ESXi Affecting Virtual Machines
CVE-2025-41226

6.8MEDIUM

Key Information:

Vendor

Vmware

Vendor
CVE Published:
20 May 2025

What is CVE-2025-41226?

VMware ESXi contains a vulnerability that allows a malicious actor with guest operation privileges to exploit a flaw during guest operations. This can lead to a denial-of-service condition for virtual machines that have VMware Tools running and guest operations enabled. The attacker must be authenticated through either vCenter Server or ESXi to trigger this vulnerability, potentially impacting the performance and availability of affected VMs.

Affected Version(s)

Cloud Foundation 5.x, 4.5.x

ESXi 8.0

ESXi 7.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-41226 : Denial-of-Service Vulnerability in VMware ESXi Affecting Virtual Machines