VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
The vulnerability results from a race condition (TOCTOU) between the moment of resource verification and the moment of its use. An attacker with local administrative privileges within the virtual machine can exploit this time window to cause an out-of-bounds write to memory buffer. This results in the possibility of arbitrary code execution within the VMX process, which runs directly on the host system, not within the isolated VM environment.
An attacker can execute arbitrary code as the VMX process on the physical host, which in practice means a complete breakdown of virtual machine (VM) isolation and potential takeover of the host system and other virtual machines.
Patches available from the vendor must be applied immediately in accordance with Broadcom Security Advisory 25390 (https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390). As a temporary measure, restrict administrative access to virtual machines exclusively to trusted users.
VMware ESXi, VMware Workstation, VMware Cloud Foundation, VMware Telco Cloud Infrastructure — versions indicated in vendor references (Broadcom Security Advisory 25390)
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HVMware Cloud Foundation
APPVmwareall versionsVMware ESXi
OSVmware7.08.0VMware Telco Cloud Infrastructure
APPVmware2.22.52.73.0VMware Telco Cloud Platform
APPVmware2.02.52.73.04.04.0.15.0VMware Workstation
APPVmware17.0 – 17.6.3 (excl.)
CISA KEV — detailsi
- Vendori
- VMware ↗
- Producti
- ESXi and Workstation
- Added to KEVi
- March 4, 2025
- Remediation deadline (US Federal)i
- March 25, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.
Related vulnerabilities
VMware vCenter: path traversal w Syslog umożliwia RCE
VMware vCenter Server — heap-overflow w DCERPC umożliwia RCE
Heap overflow w VMware vCenter Server via protokół DCERPC — RCE
RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection
VMware vCenter Server — dowolne przesyłanie plików w usłudze Analytics (RCE)