CVE-2025-22224
VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 25 March 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 1.56% probability · 74th percentile
- CISA KEV
- Listed 4 March 2025 · due 25 March 2025
- Weakness
- CWE-367
- Affected
- vmware/esxi · vmware/cloud foundation · vmware/telco cloud infrastructure · vmware/telco cloud platform · vmware/workstation
- Source
- security@vmware.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390 ; https://nvd.nist.gov/vuln/detail/CVE-2025-22224
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.