peter bassill · operator
$ cve CVE-2025-22224 JSON

CVE-2025-22224 KEV

9.3
CRITICAL · CVSS 3.1 · EPSS 1.6% (pctl 74)

Patch first

On CISA KEV — known exploited in the wild, due 2025-03-25.

Description

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

Scoring

CVSS9.3 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS1.56% — more likely to be exploited than 74% of all CVEs
WeaknessCWE-367
On CISA KEVyes — remediate by 2025-03-25
Public exploitnone known
Published2025-03-04
Last modified2026-06-17

CISA KEV

NameVMware ESXi and Workstation TOCTOU Race Condition Vulnerability
Added2025-03-04
Due2025-03-25
Vendor / productVMware / ESXi and Workstation
Ransomware usenone reported

Affected (5)

VendorProduct
vmwarecloud foundation
vmwareesxi
vmwaretelco cloud infrastructure
vmwaretelco cloud platform
vmwareworkstation

References

→ the Explorer  ·  watch your stack  ·  NVD