Junglewise Threat Intelligence

CVE-2025-22226: VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

CVE-2025-22226 · Severity: critical · CVSS 7.1 · Exploited in the wild · Published 2025-03-04

Technologies: VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware ESXi. Vendors: VMware.

Executive brief

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in the Host-Guest File System (HGFS). A malicious actor with administrative privileges on a virtual machine can exploit this to leak memory from the vmx process.

Affected products

  • VMware ESXi 7.0, 8.0
  • VMware Workstation 17.0 to 17.6.3
  • VMware Fusion 13.0.0 to 13.6.3
  • VMware Cloud Foundation
  • VMware Telco Cloud Infrastructure 2.2, 2.5, 2.7, 3.0
  • VMware Telco Cloud Platform 2.0, 2.5, 2.7, 3.0, 4.0, 4.0.1, 5.0

Timeline

  • 2025-03-04: disclosed
  • 2025-03-04: advisory
  • 2025-03-04: kev added: Added to CISA KEV catalog
  • 2025-03-04: exploited: Reported as exploited in the wild per CISA KEV inclusion.

Related threats