Junglewise Threat Intelligence

CVE-2025-62627: AMD ionic cloud driver untrusted pointer dereference in VMWare ESXi

CVE-2025-62627 · Severity: info · CVSS 7.2 · Published 2026-05-13

Technologies: Amd ionic cloud driver for VMware ESXi. Vendors: Amd.

Executive brief

A security vulnerability exists in the AMD ionic cloud driver used by VMware ESXi virtualization software. An attacker operating a low-privileged virtual machine could exploit this flaw to access sensitive data stored in the server's main memory or data belonging to other virtual machines running on the same physical hardware. This could lead to the theft of confidential information or cause system instability.

Technical details

The vulnerability is classified as an untrusted pointer dereference (CWE-822) within the AMD ionic cloud driver for VMware ESXi. An attacker with low-privileged access to a guest virtual machine can trigger the driver to dereference a pointer that is not properly validated. This allows for unauthorized read access to host kernel memory or the memory space of co-located guest VMs. Successful exploitation could result in a complete loss of confidentiality for sensitive memory data and a high impact on system availability. The attack requires local access to a guest VM but does not require user interaction.

Affected products

  • AMD ionic cloud driver for VMWare ESXi

Timeline

  • 2026-05-13: disclosed: Initial publication of the CVE and AMD security bulletin.

References

Related threats