VMware Patch Party: Crushing Critical Zero-Day Bugs from Pwn2Own 2025!

VMware fixed four zero-day vulnerabilities in ESXi, Workstation, Fusion, and Tools after they were exploited at Pwn2Own Berlin 2025. Three flaws scored a jaw-dropping severity of 9.3, letting guest programs crash the host’s party. The fourth, a mere 7.1, politely leaked information. Update now or risk being the next Pwn2Own exhibit!

Pro Dashboard

Hot Take:

VMware just patched up some zero-day holes that were bigger than a black hole in a cheese factory! With flaws rated at a whopping 9.3, it’s safe to say hackers at Pwn2Own Berlin had a very profitable and thrilling May 2025. Now, if only VMware could patch up the holes in my weekend plans…

Key Points:

  • Four zero-day vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools were patched.
  • Three critical flaws allow guest VM programs to execute commands on the host.
  • These critical flaws are CVE-2025-41236, CVE-2025-41237, and CVE-2025-41238.
  • The fourth flaw, CVE-2025-41239, is an information disclosure vulnerability.
  • VMware recommends updating to the latest software versions, as no workarounds are available.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?