Rewterz

Cobalt Strike Malware – Active IOCs

July 17, 2025
Rewterz

Multiple Microsoft Products Vulnerabilities

July 17, 2025

Multiple VMware Products Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2025-41239 CVSS:7.1

VMware ESXi, Workstation, Fusion, and VMware Tools could allow a local attacker to obtain sensitive information, caused by the usage of an uninitialised memory in vSockets. An attacker could exploit this issue to leak memory from processes communicating with vSockets.

CVE-2025-41238 CVSS:9.3

VMware ESXi, Workstation, and Fusion are vulnerable to a heap-based buffer overflow in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. An attacker could exploit this vulnerability to execute code on the host.

CVE-2025-41237 CVSS:9.3

VMware ESXi, Workstation, and Fusion could allow a local attacker to execute arbitrary code on the system, caused by an integer underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. An attacker could exploit this vulnerability to execute code on the host.

CVE-2025-41236 CVSS:9.3

VMware ESXi, Workstation, and Fusion could allow a local attacker to execute arbitrary code on the system, caused by an integer overflow in the VMXNET3 virtual network adapter. An attacker could exploit this vulnerability to execute code on the host.

Impact

  • Gain Access
  • Code Execution
  • Buffer Overflow
  • Information Disclosure

Indicators of Compromise

CVE

  • CVE-2025-41239

  • CVE-2025-41238

  • CVE-2025-41237

  • CVE-2025-41236

Affected Vendors

VMware

Affected Products

  • VMware ESXi 7.0
  • VMware ESXi 8.0
  • VMware Workstation 17.x
  • VMware Fusion 13.x
  • VMware vSphere Foundation 9.0.0.0
  • VMware Cloud Foundation 5.x - 4.5.x
  • VMware Telco Cloud Platform 5.x - 4.x - 3.x - 2.x
  • VMware Telco Cloud Infrastructure 3.x - 2.x
  • VMware Tools 13.x.x
  • VMware Tools 12.x.x - 11.x.x
  • VMware Cloud Foundation 9.0.0.0 - 5.x - 4.5.x

Remediation

Refer to VMware Security Advisory for patch, upgrade or suggested workaround information.

VMware Security Advisory

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.