VDB

CVE-2025-41238

CVE-2025-41238 PUBLISHED

On July 15, 2025, Broadcom released a critical VMware Security Advisory (VMSA), VMSA-2025-0013, addressing security vulnerabilities found and resolved as part of the response to the Pwn2Own 2025 event in Berlin, Germany. The VMSA will always be the source of truth for which products and versions are affected and the proper patches to keep your organization secure. This document is a supplement to the advisory and includes self-service information to help you and your organization decide how to respond. You are affected if you are running any version of VMware ESX, VMware vSphere, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Workstation, VMware Fusion, or VMware Tools prior to the versions listed as "fixed" in the VMSA. Please consult the VMSA itself for the definitive list of affected versions. If you have a question about whether you are affected, it is probable that you are and should take action immediately.

EPSS 0.39% · 32.1th percentile

Risk Scores

EPSS Score
0.39%
32.1th percentile

Timeline

  • Jul 15, 2025 CVE Published
  • Jul 15, 2025 Coalition ESS Score
  • Jul 15, 2025 PoC Published
  • Jul 15, 2025 PoC Published
  • Jul 16, 2025 EPSS Score
  • Jul 16, 2025 PoC Published
  • Jul 16, 2025 PoC Published
  • Jul 16, 2025 PoC Published
  • Jul 16, 2025 PoC Published
  • Jul 16, 2025 PoC Published
  • Jul 16, 2025 PoC Published
  • Jul 16, 2025 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›