VMware Patch Party: Crushing Critical Zero-Day Bugs from Pwn2Own 2025!
VMware fixed four zero-day vulnerabilities in ESXi, Workstation, Fusion, and Tools after they were exploited at Pwn2Own Berlin 2025. Three flaws scored a jaw-dropping severity of 9.3, letting guest programs crash the host’s party. The fourth, a mere 7.1, politely leaked information. Update now or risk being the next Pwn2Own exhibit!

Hot Take:
VMware just patched up some zero-day holes that were bigger than a black hole in a cheese factory! With flaws rated at a whopping 9.3, it’s safe to say hackers at Pwn2Own Berlin had a very profitable and thrilling May 2025. Now, if only VMware could patch up the holes in my weekend plans…
Key Points:
- Four zero-day vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools were patched.
- Three critical flaws allow guest VM programs to execute commands on the host.
- These critical flaws are CVE-2025-41236, CVE-2025-41237, and CVE-2025-41238.
- The fourth flaw, CVE-2025-41239, is an information disclosure vulnerability.
- VMware recommends updating to the latest software versions, as no workarounds are available.
Already a member? Log in here