Executive brief
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in the Host-Guest File System (HGFS). A malicious actor with administrative privileges on a virtual machine can exploit this to leak memory from the vmx process.
Affected products
- VMware ESXi 7.0, 8.0
- VMware Workstation 17.0 to 17.6.3
- VMware Fusion 13.0.0 to 13.6.3
- VMware Cloud Foundation
- VMware Telco Cloud Infrastructure 2.2, 2.5, 2.7, 3.0
- VMware Telco Cloud Platform 2.0, 2.5, 2.7, 3.0, 4.0, 4.0.1, 5.0
Timeline
- 2025-03-04: disclosed
- 2025-03-04: advisory
- 2025-03-04: kev added: Added to CISA KEV catalog
- 2025-03-04: exploited: Reported as exploited in the wild per CISA KEV inclusion.