Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

VMware Flaws That Earned Hackers $340,000 at Pwn2Own Patched

Four CVEs disclosed at the Pwn2Own Berlin 2025 hacking competition have been patched in VMware products.

VMware

Broadcom informed customers this week that several VMware product vulnerabilities disclosed earlier this year at the Pwn2Own hacking competition have been patched.

Participants earned more than $1 million at the Pwn2Own Berlin 2025 competition organized by Trend Micro’s Zero Day Initiative (ZDI). More than $340,000 was paid out for exploits targeting VMware products.

The STARLabs SG team earned $150,000 for exploiting a single integer overflow bug to hack VMware ESXi. 

According to Broadcom’s advisory, this critical bug impacts the VMXNET3 virtual network adapter and it can allow an attacker with local admin privileges on a VM that uses the adapter to execute arbitrary code on the host. The security hole is tracked as CVE-2025-41236.

The REverse Tactics team earned $112,500 for an ESXi exploit involving two bugs. The amount is lower than the one earned by STARLabs SG because one of the flaws was known to Broadcom. 

REverse Tactics has been credited by Broadcom for two CVEs: CVE-2025-41237, a critical out-of-bounds write vulnerability that can be exploited by a privileged attacker on a VM to execute arbitrary code on the host, and CVE-2025-41239, a high-severity issue that allows a privileged attacker to leak memory.

Advertisement. Scroll to continue reading.

A researcher from Theori, a company that was also represented at Pwn2Own but did not target VMware, has also been credited for independently discovering CVE-2025-41239.

Lastly, the Synacktiv team earned $80,000 at Pwn2Own for a VMware Workstation exploit. Broadcom’s advisory credits Synacktiv for CVE-2025-41238, a critical out-of-bounds write issue that can allow an attacker with local admin privileges on a VM to execute arbitrary code on the host. 

The vendor has released patches for these vulnerabilities for VMware ESXi, Workstation, Fusion, Cloud Foundation, XSphere Foundation, Telco Cloud Platform, and Tools. 

In a separate FAQ document, Broadcom said it has no evidence that these vulnerabilities have been exploited in the wild. 

Industrial giant Rockwell Automation on Wednesday also published an advisory to inform customers about these VMware vulnerabilities. Several Rockwell products that may use VMware components are impacted, including Industrial Data Center (IDC), VersaVirtual Appliance (VVA), Threat Detection Managed Services (TDMS), Endpoint Protection Service, and Engineered and Integrated Solutions.

Related: NATO-Flagged Vulnerability Tops Latest VMware Security Patch Batch

Related: Vulnerabilities Patched by Juniper, VMware and Zoom

Related: Vulnerabilities Patched by Ivanti, VMware, Zoom

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Sumo Logic has appointed Chris Malone as CEO and Conor Burns as CFO.

Nozomi Networks has appointed co-founder Andrea Carcano as CEO.

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.