Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»VMWARE PWN2OWN Cures Four ESXI zero-day bugs in Berlin
    Security

    VMWARE PWN2OWN Cures Four ESXI zero-day bugs in Berlin

    PineapplesUpdateBy PineapplesUpdateJuly 17, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    VMWARE PWN2OWN Cures Four ESXI zero-day bugs in Berlin
    Share
    Facebook Twitter LinkedIn Pinterest Email

    VMWARE PWN2OWN Cures Four ESXI zero-day bugs in Berlin

    VMware fixed four weaknesses in VMWARE ESXI, Workstation, Fusion and equipment in May 2025 in May 2025 during the PWN2OWN Berlin 2025 hacking competition.

    The severity of three of the packed flaws is rating 9.3, as they allow a guest virtual machine programs to execute the command on the host. These flaws are tracked as CVE-2025-41236, CVE-2025-41237, and CVE-2025-41238.

    These defects are described Security advisor As:

    • Cve-2025-41236: VMWARE ESXI, Workstation, and VMXNET3 virtual network adapters in fusion include an integer-overflow vulnerability. Starlabes SG’s Guyen Hoang Tachch used this defect in PWN2OWN.
    • Cve-2025-41237: VMware ESXI, Workstation, and Fusion have an integer-underflow in VMCI (virtual machine communication interface) that leads to an out-of-bound right. This defect was used by Corentine Beet of reverse strategy in PWN2OWN.
    • Cve-2025-41238: VMware ESXI, Workstation, and Fusion PVSCSI (Paravirtuulized Scsi) Controller has a heap-overplane vulnerability, which leads to writing one-bound. A malicious actor with local administrative privileges on a virtual machine can exploit the issue to perform the VMX process of the virtual machine to execute the code. Thomas Bouzerrar and Etienne Helluy-Lafont of Synacktiv in PWN2OWN used this defect.

    The fourth defect tracked as CVE-2025–41239 received a 7.1 rating as it is an information disclosure. It was also discovered by Corentin Bayet of reverse strategy, who chained with CVE-2025–41237 during the hacking competition.

    VMWARE has not provided any work -round, and the only way to fix these weaknesses is to install new versions of software.

    It should be noted that CVE-2025-41239 affects the VMware tool for Windows, which requires a one. Separate upgrading process,

    These weaknesses were displayed as zero-days during the PWN2OWN Berlin 2025 hacking competition, where security researchers collected $ 1,078,750 after exploiting 29 zero-day weaknesses.


    Knowledgeable

    CISOS knows how to purchase a board begins with a clear, strategic approach how the cloud safety runs the business price.

    This helps to introduce the risk, impact and priorities to the free, editable board report deck deck security leaders in clear business terms. Convert security updates into meaningful conversations and take fast decision in boardroom.

    Berlin bugs cures ESXI pwn2own Vmware zeroday
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHere is coming on your device in the next batch of emoji
    Next Article Why you should brow to your air fryer instead of your oven
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Your Uber driver has a new endeavor: training an AI for cash

    October 18, 2025
    Security

    American Airlines subsidiary Envoy confirms Oracle data breach attack

    October 18, 2025
    Security

    Government considers destroying its data hub after decade-long intrusion

    October 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.