CVE-2025-22224

Confirmed PUBLISHED

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious...

Vendor: VMware Product: ESXi, Workstation, VMware Cloud Foundation, Telco Cloud Platform, Telco Cloud Infrastructure
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.3 Critical EPSS 1.5%

At a Glance

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

nessus_scanner cisa
CVE Published
Mar 04, 2025
Exploitation Reported
Mar 04, 2025
CVSS
9.3 Critical
EPSS
1.5%
Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
VMware
ESXi

8.0 to < ESXi80U3d-24585383

Affected
VMware
ESXi

8.0 to < ESXi80U2d-24585300

Affected
VMware
ESXi

7.0 to < ESXi70U3s-24585291

Affected
VMware
Workstation

17.x to < 17.6.3

Affected
VMware
VMware Cloud Foundation

5.x, 4.5.x

Affected
VMware
Telco Cloud Platform

5.x, 4.x, 3.x, 2.x

Affected
VMware
Telco Cloud Infrastructure

3.x, 2.x

Affected

CVE References