Multiple Microsoft Windows Products Vulnerabilities
May 21, 2025Multiple D-Link DI-7003GV2 Vulnerabilities
May 21, 2025Multiple Microsoft Windows Products Vulnerabilities
May 21, 2025Multiple D-Link DI-7003GV2 Vulnerabilities
May 21, 2025Severity
Medium
Analysis Summary
CVE-2025-41225 CVSS:8.8
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script actions may exploit this issue to run arbitrary commands on the vCenter Server.
CVE-2025-41226 CVSS:6.8
VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools running and guest operations enabled.
CVE-2025-41227 CVSS:5.5
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service condition.
CVE-2025-41228 CVSS:4.3
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.
Impact
- Denial of Service
- Cross-Site Scripting
Indicators of Compromise
CVE
CVE-2025-41225
CVE-2025-41226
CVE-2025-41227
CVE-2025-41228
Affected Vendors
Affected Products
- Broadcom VMware vCenter Server - 8.0
- VMware ESXi - 8.0
- VMware ESXi - 7.0
- VMware vCenter Server - 7.0
- VMware Cloud Foundation (vCenter) - 5.x
- VMware Cloud Foundation (vCenter) - 4.5.x
- VMware Cloud Foundation (ESXi) - 4.5.x
- VMware Telco Cloud Infrastructure (ESXi) - 3.x
- VMware Telco Cloud Infrastructure (ESXi) - 2.x
- VMware Telco Cloud Platform (vCenter) - 5.x 4.x 3.x 2.x
- VMware Telco Cloud Infrastructure (vCenter) - 3.x
- VMware Telco Cloud Infrastructure (vCenter) - 2.x
- VMware Workstation - 17.x
- VMware Fusion - 13.x
Remediation
Refer to VMware Security Advisory for patch, upgrade, or suggested workaround information.