HIGH

CVE-2025-22225

Vmware Esxi 2025-03-04 CVSS v3.1
CVSS
8.2
KEV

Description

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

Summary dbcve.org

VMware ESXi contains an arbitrary write vulnerability in the VMX process (the virtualization machine monitor). An attacker with VMX-level privileges can write to arbitrary kernel memory, escaping the VM sandbox and potentially gaining host-level code execution.

Mitigation

Apply VMware security patches for CVE-2025-22225 to all affected ESXi hosts. Coordinate maintenance windows to migrate VMs, apply patches, and reboot hypervisors.

Weakness (CWE)

CWE-787 Out-of-bounds Write
CWE-123

EPSS Score

1%
Probability of exploitation in next 30 days
60.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE