CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2025-22224

CVSS 9.3v3.1pub. 2025-03-04upd. 2025-10-30

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

🤖 AI Analysis
How it works

The vulnerability results from a race condition (TOCTOU) between the moment of resource verification and the moment of its use. An attacker with local administrative privileges within the virtual machine can exploit this time window to cause an out-of-bounds write to memory buffer. This results in the possibility of arbitrary code execution within the VMX process, which runs directly on the host system, not within the isolated VM environment.

Impact

An attacker can execute arbitrary code as the VMX process on the physical host, which in practice means a complete breakdown of virtual machine (VM) isolation and potential takeover of the host system and other virtual machines.

Mitigation & patch

Patches available from the vendor must be applied immediately in accordance with Broadcom Security Advisory 25390 (https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390). As a temporary measure, restrict administrative access to virtual machines exclusively to trusted users.

Who is affected

VMware ESXi, VMware Workstation, VMware Cloud Foundation, VMware Telco Cloud Infrastructure — versions indicated in vendor references (Broadcom Security Advisory 25390)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • VMware Cloud Foundation

    APP
    Vmware
    all versions
  • VMware ESXi

    OS
    Vmware
    7.08.0
  • VMware Telco Cloud Infrastructure

    APP
    Vmware
    2.22.52.73.0
  • VMware Telco Cloud Platform

    APP
    Vmware
    2.02.52.73.04.04.0.15.0
  • VMware Workstation

    APP
    Vmware
    17.0 – 17.6.3 (excl.)

CISA KEV — detailsi

Vendori
VMware
Producti
ESXi and Workstation
Added to KEVi
March 4, 2025
Remediation deadline (US Federal)i
March 25, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 25 marca 2025
Tags
MemoryRace Condition
CWE
References

Related vulnerabilities

CVE-2026-59310CRITICAL9.8⚠ KEVPL ✓same product

VMware vCenter: path traversal w Syslog umożliwia RCE

CVE-2024-38812CRITICAL9.8⚠ KEVPL ✓same product

VMware vCenter Server — heap-overflow w DCERPC umożliwia RCE

CVE-2024-37079CRITICAL9.8⚠ KEVPL ✓same product

Heap overflow w VMware vCenter Server via protokół DCERPC — RCE

CVE-2022-22954CRITICAL9.8⚠ KEVPL ✓same product

RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection

CVE-2021-22005CRITICAL9.8⚠ KEVPL ✓same product

VMware vCenter Server — dowolne przesyłanie plików w usłudze Analytics (RCE)