CVE-2025-41239: VMware Cloud Foundation

High severity, CVSS 7.1. EPSS: 3% chance of exploitation in the next 30 days.

VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets.

Affected products

  • VMware Cloud Foundation
  • VMware ESXi
  • VMware Fusion: from 13, before 13.6.4 (fixed in 13.6.4)
  • VMware Telco Cloud Infrastructure
  • VMware Telco Cloud Platform
  • VMware Tools: from 13.x.x, before 13.0.1.0 (fixed in 13.0.1.0)
  • VMware Workstation: from 17, before 17.6.4 (fixed in 17.6.4)

Published 2025-07-15. Last modified 2026-06-17.