8.2

CVE-2025-22224

Warnung
Medienbericht
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ ESXi Version 7.0 Update -
VMware ≫ ESXi Version 7.0 Update beta
VMware ≫ ESXi Version 7.0 Update update_1
VMware ≫ ESXi Version 7.0 Update update_1a
VMware ≫ ESXi Version 7.0 Update update_1b
VMware ≫ ESXi Version 7.0 Update update_1c
VMware ≫ ESXi Version 7.0 Update update_1d
VMware ≫ ESXi Version 7.0 Update update_1e
VMware ≫ ESXi Version 7.0 Update update_2
VMware ≫ ESXi Version 7.0 Update update_2a
VMware ≫ ESXi Version 7.0 Update update_2c
VMware ≫ ESXi Version 7.0 Update update_2d
VMware ≫ ESXi Version 7.0 Update update_2e
VMware ≫ ESXi Version 7.0 Update update_3
VMware ≫ ESXi Version 7.0 Update update_3c
VMware ≫ ESXi Version 7.0 Update update_3d
VMware ≫ ESXi Version 7.0 Update update_3e
VMware ≫ ESXi Version 7.0 Update update_3f
VMware ≫ ESXi Version 7.0 Update update_3g
VMware ≫ ESXi Version 7.0 Update update_3i
VMware ≫ ESXi Version 7.0 Update update_3j
VMware ≫ ESXi Version 7.0 Update update_3k
VMware ≫ ESXi Version 7.0 Update update_3l
VMware ≫ ESXi Version 7.0 Update update_3m
VMware ≫ ESXi Version 7.0 Update update_3n
VMware ≫ ESXi Version 7.0 Update update_3o
VMware ≫ ESXi Version 7.0 Update update_3p
VMware ≫ ESXi Version 7.0 Update update_3q
VMware ≫ ESXi Version 7.0 Update update_3r
VMware ≫ ESXi Version 8.0 Update -
VMware ≫ ESXi Version 8.0 Update a
VMware ≫ ESXi Version 8.0 Update b
VMware ≫ ESXi Version 8.0 Update c
VMware ≫ ESXi Version 8.0 Update update_1
VMware ≫ ESXi Version 8.0 Update update_1a
VMware ≫ ESXi Version 8.0 Update update_1c
VMware ≫ ESXi Version 8.0 Update update_1d
VMware ≫ ESXi Version 8.0 Update update_2
VMware ≫ ESXi Version 8.0 Update update_2b
VMware ≫ ESXi Version 8.0 Update update_2c
VMware ≫ ESXi Version 8.0 Update update_3
VMware ≫ ESXi Version 8.0 Update update_3b
VMware ≫ ESXi Version 8.0 Update update_3c
VMware ≫ Cloud Foundation Version -
VMware ≫ Telco Cloud Platform Version 2.0
VMware ≫ Telco Cloud Platform Version 2.5
VMware ≫ Telco Cloud Platform Version 2.7
VMware ≫ Telco Cloud Platform Version 3.0
VMware ≫ Telco Cloud Platform Version 4.0
VMware ≫ Telco Cloud Platform Version 4.0.1
VMware ≫ Telco Cloud Platform Version 5.0
VMware ≫ Workstation Version >= 17.0 < 17.6.3

04.03.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

VMware ESXi and Workstation TOCTOU Race Condition Vulnerability

Schwachstelle

VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.56% 0.728
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
VMware 9.3 2.5 6
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
12.08.2025 11:52
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-22224
US Government Resource