CyberSec.Space Logo
Back to CVE Browser

CVE-2025-22224

🔥 Known Exploited (CISA KEV)CRITICAL
9.3
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-03-04
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

Affected Platforms (CPE)

💻
Vmware

Esxi

= 7.0= 8.0
📦
Vmware

Cloud Foundation

All versions
📦
Vmware

Telco Cloud Infrastructure

= 2.2= 2.5= 2.7= 3.0
📦
Vmware

Telco Cloud Platform

= 2.0= 2.5= 2.7= 3.0= 4.0= 4.0.1= 5.0

References & Advisories

Related Security Intelligence Articles

Related Vulnerabilities