Top Advisory

Multiple Vulnerabilities in VMware ESXi

Severity Level: High

Date: 12/09/2023

Ref: CERT/NCSOC/23/0193

Components Affected

Overview

Multiple high-severity vulnerabilities were identified in VMware products as part of the Pwn2Own Berlin 2025 event. These flaws allow attackers with administrative access inside virtual machines to potentially execute code on the host system, leading to privilege escalation and information leakage.

Description

Impact

Solution / Workarounds

Before installation of the software, please visit the vendor's website for more details.

Apply fixes issued by VMware:

Reference

Disclaimer

The information provided herein is on an "as is" basis, without warranty of any kind.

Footer Advisory