CVE-2025-22224
CRITICAL CISA KEVDescription
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | esxi |
| vmware | cloud_foundation |
| vmware | telco_cloud_infrastructure |
| vmware | telco_cloud_infrastructure |
| vmware | telco_cloud_infrastructure |
| vmware | telco_cloud_infrastructure |
| vmware | telco_cloud_platform |
| vmware | telco_cloud_platform |
| vmware | telco_cloud_platform |
| vmware | telco_cloud_platform |
| vmware | telco_cloud_platform |
| vmware | telco_cloud_platform |
| vmware | telco_cloud_platform |
| vmware | workstation |
References
Frequently Asked Questions
What is CVE-2025-22224? +
How severe is CVE-2025-22224? +
What products are affected by CVE-2025-22224? +
How do I check if I'm vulnerable to CVE-2025-22224? +
Related Vulnerabilities
When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations …
MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) …
Duende.AccessTokenManagement is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. Duende.AccessTokenManagement contains a race condition …
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could …
conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. In versions prior to 2025.4.10, a race …
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at …