CVE-2025-22224
Description
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Summary dbcve.org
VMware ESXi and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) race condition vulnerability that leads to an out-of-bounds memory write. A malicious actor with local administrative privileges on a virtual machine can exploit this race condition to write beyond allocated memory bounds and execute arbitrary code as the VMX process on the host, achieving VM escape.
Mitigation
Apply VMware security patches for ESXi and Workstation as soon as possible; restrict local administrative privileges on virtual machines and monitor for suspicious VMX process activity as defense-in-depth.