CVE-2025-22224

Confirmed PUBLISHED

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious...

VMware · ESXi, Workstation, VMware Cloud Foundation, Telco Cloud Platform, Telco Cloud Infrastructure
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.3 Critical

At a Glance

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

nessus_scanner cisa
CVE Published
Mar 04, 2025
Exploitation Reported
Mar 04, 2025
CVSS
9.3 Critical
EPSS
Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
VMware
ESXi

8.0 to < ESXi80U3d-24585383

Affected
VMware
ESXi

8.0 to < ESXi80U2d-24585300

Affected
VMware
ESXi

7.0 to < ESXi70U3s-24585291

Affected
VMware
Workstation

17.x to < 17.6.3

Affected
VMware
VMware Cloud Foundation

5.x, 4.5.x

Affected
VMware
Telco Cloud Platform

5.x, 4.x, 3.x, 2.x

Affected
VMware
Telco Cloud Infrastructure

3.x, 2.x

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.