CVE-2025-22226 is an information disclosure vulnerability in VMware ESXi, Workstation, and Fusion, stemming from an out-of-bounds read in HGFS. An attacker with administrative privileges to a virtual machine can exploit this to leak memory from the vmx process. Rated Medium (CVSS 6.0), it requires high privileges but has a high impact on confidentiality. This vulnerability is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog and extensive media coverage, despite a lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:-:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:beta:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:update_1:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:update_1a:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:7.0:update_1b:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in VMware ESXi Components (VMSA-2025-0004)
Jan 1, 2025Multiple vulnerabilities in VMware ESXi components (VMSA-2025-0004)
Multiple vulnerabilities in VMware ESXi components (VMSA-2025-0004)