CVE-2025-22226

Confirmed PUBLISHED

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious...

VMware · ESXi, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.1 High

At a Glance

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

cisa nessus_scanner
CVE Published
Mar 04, 2025
Exploitation Reported
Mar 04, 2025
CVSS
7.1 High
EPSS
Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
ESXi

8.0 to < ESXi80U3d-24585383

Affected
n/a
ESXi

8.0 to < ESXi80U2d-24585300

Affected
n/a
ESXi

7.0 to < ESXi70U3s-24585291

Affected
n/a
VMware Workstation

17.x to < 17.6.3

Affected
n/a
VMware Fusion

13.x to < 13.6.3

Affected
n/a
VMware Cloud Foundation

5.x, 4.5.x

Affected
n/a
VMware Telco Cloud Platform

5.x, 4.x, 3.x, 2.x

Affected
n/a
VMware Telco Cloud Infrastructure

3.x, 2.x

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.