MEDIUM
CVE-2025-22226
CVSS
6
KEV
Description
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
Summary dbcve.org
Out-of-bounds read vulnerability in HGFS (Host-Guest File System) component of VMware ESXi, Workstation, and Fusion allows a VM administrator to leak memory from the vmx process.
Mitigation
Apply vendor patches when available; until then, restrict administrative privileges on virtual machines and consider disabling HGFS if not required.
Weakness (CWE)
CWE-125
Out-of-bounds Read
EPSS Score
1.74%
Probability of exploitation in next 30 days
76.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.