Several critical security flaws within VMware Cloud Foundation could enable cybercriminals to compromise sensitive information and carry out unauthorized operations.
These vulnerabilities, identified as CVE-2025-41229, CVE-2025-41230, and CVE-2025-41231, come with CVSS scores ranging from 7.3 to 8.2, presenting substantial threats to organizations running the affected versions of VMware Cloud Foundation.
Directory Traversal Flaw Unveils Internal Services
According to Broadcom, the most critical of these vulnerabilities (CVE-2025-41229) involves a directory traversal exploit with a CVSS base score of 8.2. This flaw enables attackers with access to port 443 of VMware Cloud Foundation to bypass intended directory restrictions and gain access to internal services meant to be off-limits.
What’s particularly alarming is that this vulnerability can be exploited without any user interaction, which increases the risk for systems exposed to the internet.
Security analysts have observed that exploiting this flaw follows a predictable pattern similar to:

This exploit enables attackers to circumvent path restrictions and access critical system components, which could result in unauthorized access.
VMware has acknowledged that versions 4.5.x and 5.x of Cloud Foundation are affected and need immediate patching to mitigate the risk.
Sensitive Information Leak Through Disclosure Vulnerability
The second identified flaw (CVE-2025-41230) carries a CVSS score of 7.5 and revolves around information leakage.
This issue allows attackers to retrieve sensitive data by sending a specially crafted API request to port 443.
Exposed information may include authentication tokens, system configurations, and other critical details, all of which could serve as stepping stones for further exploitation.
Exploiting this flaw could involve techniques such as:

Security professionals caution that this flaw could serve as a key entry point for multi-phase attacks targeting VMware infrastructure, enabling attackers to gather crucial intelligence.
Lack of Proper Authorization Leads to Unauthorized Operations
The third vulnerability (CVE-2025-41231), which has a CVSS score of 7.3, arises from inadequate authorization checks within the VMware Cloud Foundation system.
Once attackers have gained access to the appliance, they can exploit this weakness to carry out unauthorized operations and access data that should remain out of their reach.
This flaw specifically affects the internal authorization mechanism, which, without proper validation, allows attackers to escalate their privileges and manipulate system resources, jeopardizing the security of the entire virtualized environment.
Gustavo Bonito from the NATO Cyber Security Centre (NCSC) is credited with discovering and notifying VMware about all three vulnerabilities.
| CVE ID | Affected Products | Impact | Exploit Prerequisites | CVSS 3.1 Score |
|---|---|---|---|---|
| CVE-2025-41229 | VMware Cloud Foundation 4.5.x, 5.x | Directory traversal, allowing unauthorized access to internal services | Network access to port 443 on Cloud Foundation | 8.2 (High) |
| CVE-2025-41230 | VMware Cloud Foundation 4.5.x, 5.x | Information leak through API, exposing sensitive data | Network access to port 443 on Cloud Foundation | 7.5 (High) |
| CVE-2025-41231 | VMware Cloud Foundation 4.5.x, 5.x | Missing authorization controls, enabling privilege escalation | Access to Cloud Foundation appliance | 7.3 (High) |
Recommended Action
VMware has issued updates to resolve these vulnerabilities in VMware Cloud Foundation version 5.x with release 5.2.1.2.
For users on version 4.5.x, patches can be found via KB398008. The company urges prompt installation of these patches, as there are no alternative solutions to mitigate the identified issues.
Experts stress the importance of prioritizing these updates due to the severity of the vulnerabilities and their potential impact on enterprise-level virtualization infrastructure. The high CVSS ratings underscore the critical need for timely action.
Organizations utilizing VMware Cloud Foundation should adopt a comprehensive security response strategy, which includes swift patch deployment, ongoing security monitoring, and a thorough examination of system logs for any signs of exploitation.



