CVE-2025-22224 is a critical Time-of-Check Time-of-Use (TOCTOU) vulnerability in VMware ESXi, Workstation, and other VMware products, leading to an out-of-bounds write. An attacker with local administrative privileges on a virtual machine can exploit this to execute code as the VMX process on the host. With a CVSS score of 8.2 (HIGH), this vulnerability allows for high impact to confidentiality, integrity, and availability with low attack complexity. This flaw is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered significant community attention and media coverage, despite no public exploit code being readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:-:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:beta:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:update_1:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:update_1a:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:update_1b:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in VMware ESXi Components (VMSA-2025-0004)
Jan 1, 2025Multiple vulnerabilities in VMware ESXi components (VMSA-2025-0004)
Multiple vulnerabilities in VMware ESXi components (VMSA-2025-0004)