peter bassill · operator
$ cve CVE-2025-22226 JSON

CVE-2025-22226 KEV

7.1
HIGH · CVSS 3.1 · EPSS 1.8% (pctl 77)

Patch first

On CISA KEV — known exploited in the wild, due 2025-03-25.

Description

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

Scoring

CVSS7.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS1.77% — more likely to be exploited than 77% of all CVEs
WeaknessCWE-125
On CISA KEVyes — remediate by 2025-03-25
Public exploitnone known
Published2025-03-04
Last modified2026-06-17

CISA KEV

NameVMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability
Added2025-03-04
Due2025-03-25
Vendor / productVMware / ESXi, Workstation, and Fusion
Ransomware usenone reported

Affected (6)

VendorProduct
vmwarecloud foundation
vmwareesxi
vmwarefusion
vmwaretelco cloud infrastructure
vmwaretelco cloud platform
vmwareworkstation

References

→ the Explorer  ·  watch your stack  ·  NVD