CVE-2025-41227: VMware Cloud Foundation
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service condition.
Affected products
- VMware Cloud Foundation
- VMware ESXi
- VMware Fusion: from 13, before 13.6.3 (fixed in 13.6.3)
- VMware Telco Cloud Infrastructure
- VMware Telco Cloud Platform
- VMware Workstation: from 17, before 17.6.3 (fixed in 17.6.3)
Published 2025-05-20. Last modified 2026-06-17.