HIGH

CVE-2025-22224

Vmware Esxi 2025-03-04 CVSS v3.1
CVSS
8.2
KEV

Description

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

Summary dbcve.org

VMware ESXi and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) race condition vulnerability that leads to an out-of-bounds memory write. A malicious actor with local administrative privileges on a virtual machine can exploit this race condition to write beyond allocated memory bounds and execute arbitrary code as the VMX process on the host, achieving VM escape.

Mitigation

Apply VMware security patches for ESXi and Workstation as soon as possible; restrict local administrative privileges on virtual machines and monitor for suspicious VMX process activity as defense-in-depth.

Weakness (CWE)

CWE-367

EPSS Score

1.56%
Probability of exploitation in next 30 days
74.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE