CVE-2025-25058 Details
Description
Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
A vulnerability allowing information disclosure has been identified in some ESXi kernel mode drivers for Intel Ethernet 800-Series products. This issue affects versions prior to 2.2.2.0 on ESXi 8.0 and versions prior to 2.2.3.0 on ESXi 9.0. The vulnerability arises from improper initialization in the drivers, which may allow an unprivileged, authenticated software adversary to expose data. The issue could potentially be exploited through local access, without special internal knowledge, and requires no user interaction.
Users are advised to update the ESXi base driver for Intel 800 Series Ethernet to version 2.2.2.0 or later on ESXi 8.0, and to version 2.2.3.0 or later on ESXi 9.0. The updated drivers are available for download from the Broadcom Compatibility Guide.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 10, 2026CISA-ADP
Assessed Feb 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01408.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-665 | Improper Initialization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Intel ESXi base driver | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 10, 2026 | New CVE Received | [email protected] |
Volerion