CVE-2025-22226
VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 25 March 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
- CVSS 3.1
- 6.0 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 1.74% probability · 76th percentile
- CISA KEV
- Listed 4 March 2025 · due 25 March 2025
- Weakness
- CWE-125
- Affected
- vmware/esxi · vmware/cloud foundation · vmware/fusion · vmware/telco cloud infrastructure · vmware/telco cloud platform · vmware/workstation
- Source
- security@vmware.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390 ; https://nvd.nist.gov/vuln/detail/CVE-2025-22226
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.