peter bassill · operator
$ cve CVE-2025-22225 JSON

CVE-2025-22225 KEV

8.2
HIGH · CVSS 3.1 · EPSS 1% (pctl 62)

Patch first

On CISA KEV — known exploited in the wild, due 2025-03-25.

Description

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

Scoring

CVSS8.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS1.02% — more likely to be exploited than 62% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2025-03-25
Public exploitnone known
Published2025-03-04
Last modified2026-08-04

CISA KEV

NameVMware ESXi Arbitrary Write Vulnerability
Added2025-03-04
Due2025-03-25
Vendor / productVMware / ESXi
Ransomware useknown

Affected (4)

VendorProduct
vmwarecloud foundation
vmwareesxi
vmwaretelco cloud infrastructure
vmwaretelco cloud platform

References

→ the Explorer  ·  watch your stack  ·  NVD