CVE-2025-41227: VMware Cloud Foundation

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service condition.

Affected products

  • VMware Cloud Foundation
  • VMware ESXi
  • VMware Fusion: from 13, before 13.6.3 (fixed in 13.6.3)
  • VMware Telco Cloud Infrastructure
  • VMware Telco Cloud Platform
  • VMware Workstation: from 17, before 17.6.3 (fixed in 17.6.3)

Published 2025-05-20. Last modified 2026-06-17.