Junglewise Threat Intelligence

CVE-2025-22225: VMware ESXi Arbitrary Write Vulnerability

CVE-2025-22225 · Severity: critical · CVSS 8.2 · Exploited in the wild · Published 2025-03-04

Technologies: VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware ESXi. Vendors: VMware.

Executive brief

VMware ESXi contains an arbitrary write vulnerability where an attacker with privileges within the VMX process can trigger a kernel write. This flaw allows for a sandbox escape, potentially granting the attacker control over the host system.

Affected products

  • VMware ESXi 7.0, 8.0
  • VMware Cloud Foundation
  • VMware Telco Cloud Infrastructure 2.2, 2.5, 2.7, 3.0
  • VMware Telco Cloud Platform 2.0, 2.5, 2.7, 3.0, 4.0, 4.0.1, 5.0

Timeline

  • 2025-03-04: disclosed: CVE received from VMware
  • 2025-03-04: advisory: Vendor advisory published by Broadcom/VMware
  • 2025-03-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-03-04: exploited: Reported as exploited in the wild per CISA KEV entry

Related threats