CVE-2025-22225 is an arbitrary kernel write vulnerability in VMware ESXi, Cloud Foundation, and Telco Cloud products. An attacker with VMX process privileges can exploit this to escape the sandbox, leading to high impact on confidentiality, integrity, and availability. This critical vulnerability (CVSS 8.2) is actively exploited in ransomware campaigns, as confirmed by its presence in CISA's KEV catalog. Despite no public exploit code, it garners significant community discussion and media coverage, indicating widespread awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:-:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:beta:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:update_1:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:update_1a:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:update_1b:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in VMware ESXi Components (VMSA-2025-0004)
Jan 1, 2025Multiple vulnerabilities in VMware ESXi components (VMSA-2025-0004)
Multiple vulnerabilities in VMware ESXi components (VMSA-2025-0004)