← All Advisories

VMware ESXi ionic cloud driver heap overflow provides a second path to privilege escalation and code execution

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2025-62623

Key Details

CVECVE-2025-62623
CVSS Score / Version8.8 (High) / CVSS v4.0
Updated2026-06-17
Classified asCWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)

What to Know

A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-62623
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-62623