6

CVE-2025-22226

Warnung
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ ESXi Version 7.0 Update -
VMware ≫ ESXi Version 7.0 Update beta
VMware ≫ ESXi Version 7.0 Update update_1
VMware ≫ ESXi Version 7.0 Update update_1a
VMware ≫ ESXi Version 7.0 Update update_1b
VMware ≫ ESXi Version 7.0 Update update_1c
VMware ≫ ESXi Version 7.0 Update update_1d
VMware ≫ ESXi Version 7.0 Update update_1e
VMware ≫ ESXi Version 7.0 Update update_2
VMware ≫ ESXi Version 7.0 Update update_2a
VMware ≫ ESXi Version 7.0 Update update_2c
VMware ≫ ESXi Version 7.0 Update update_2d
VMware ≫ ESXi Version 7.0 Update update_2e
VMware ≫ ESXi Version 7.0 Update update_3
VMware ≫ ESXi Version 7.0 Update update_3c
VMware ≫ ESXi Version 7.0 Update update_3d
VMware ≫ ESXi Version 7.0 Update update_3e
VMware ≫ ESXi Version 7.0 Update update_3f
VMware ≫ ESXi Version 7.0 Update update_3g
VMware ≫ ESXi Version 7.0 Update update_3i
VMware ≫ ESXi Version 7.0 Update update_3j
VMware ≫ ESXi Version 7.0 Update update_3k
VMware ≫ ESXi Version 7.0 Update update_3l
VMware ≫ ESXi Version 7.0 Update update_3m
VMware ≫ ESXi Version 7.0 Update update_3n
VMware ≫ ESXi Version 7.0 Update update_3o
VMware ≫ ESXi Version 7.0 Update update_3p
VMware ≫ ESXi Version 7.0 Update update_3q
VMware ≫ ESXi Version 7.0 Update update_3r
VMware ≫ ESXi Version 8.0 Update -
VMware ≫ ESXi Version 8.0 Update a
VMware ≫ ESXi Version 8.0 Update b
VMware ≫ ESXi Version 8.0 Update c
VMware ≫ ESXi Version 8.0 Update update_1
VMware ≫ ESXi Version 8.0 Update update_1a
VMware ≫ ESXi Version 8.0 Update update_1c
VMware ≫ ESXi Version 8.0 Update update_1d
VMware ≫ ESXi Version 8.0 Update update_2
VMware ≫ ESXi Version 8.0 Update update_2b
VMware ≫ ESXi Version 8.0 Update update_2c
VMware ≫ ESXi Version 8.0 Update update_3
VMware ≫ ESXi Version 8.0 Update update_3b
VMware ≫ ESXi Version 8.0 Update update_3c
VMware ≫ Cloud Foundation Version -
VMware ≫ Fusion Version >= 13.0.0 < 13.6.3
VMware ≫ Telco Cloud Platform Version 2.0
VMware ≫ Telco Cloud Platform Version 2.5
VMware ≫ Telco Cloud Platform Version 2.7
VMware ≫ Telco Cloud Platform Version 3.0
VMware ≫ Telco Cloud Platform Version 4.0
VMware ≫ Telco Cloud Platform Version 4.0.1
VMware ≫ Telco Cloud Platform Version 5.0
VMware ≫ Workstation Version >= 17.0 < 17.6.3

04.03.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

Schwachstelle

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.74% 0.754
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6 1.5 4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
VMware 7.1 2.5 4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-22226
US Government Resource