VMware Security Updates – 16 Jul 2025

VMware has released security updates to fix several vulnerabilities across multiple VMware products.

The addressed vulnerabilities could allow the local attacker with administrative privileges to obtain sensitive information, or execute arbitrary code and gain access to the affected product.

1. VMware ESXi, Workstation, and Fusion Integer Overflow Vulnerability (CVE-2025-41236):

  • CVSS: 9.3
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Access

2. VMware ESXi, Workstation, Fusion, and VMware Tools Information Disclosure Vulnerability (CVE-2025-41236):

  • CVSS: 7.1
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information

Sample of affected products:

  • VMware Telco Cloud Infrastructure.
  • VMware Cloud Foundation.
  • VMware Workstation Pro.
Vulnerabilities
  • CVE-2025-22243
  • CVE-2025-22244
  • CVE-2025-22245
  • CVE-2025-41236
  • CVE-2025-41237
  • CVE-2025-41238
  • CVE-2025-41239
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Updates

References