Executive brief
VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine can exploit this to execute code as the VMX process on the host.
Affected products
- VMware ESXi 7.0, 8.0
- VMware Workstation 17.0 to 17.6.3
- VMware Cloud Foundation
- VMware Telco Cloud Infrastructure 2.2, 2.5, 2.7, 3.0
- VMware Telco Cloud Platform 2.0, 2.5, 2.7, 3.0, 4.0, 4.0.1, 5.0
Timeline
- 2025-03-04: disclosed
- 2025-03-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-03-04: exploited: Reported as exploited in the wild.
- 2025-03-04: advisory: VMware/Broadcom published security advisory.