CVE-2025-22224 KEV
9.3
CRITICAL · CVSS 3.1 · EPSS 1.6% (pctl 74)
Patch first
On CISA KEV — known exploited in the wild, due 2025-03-25.
Description
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Scoring
| CVSS | 9.3 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 1.56% — more likely to be exploited than 74% of all CVEs |
| Weakness | CWE-367 |
| On CISA KEV | yes — remediate by 2025-03-25 |
| Public exploit | none known |
| Published | 2025-03-04 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | VMware ESXi and Workstation TOCTOU Race Condition Vulnerability |
|---|---|
| Added | 2025-03-04 |
| Due | 2025-03-25 |
| Vendor / product | VMware / ESXi and Workstation |
| Ransomware use | none reported |
Affected (5)
| Vendor | Product |
|---|---|
| vmware | cloud foundation |
| vmware | esxi |
| vmware | telco cloud infrastructure |
| vmware | telco cloud platform |
| vmware | workstation |
References
→ the Explorer · watch your stack · NVD