6
CVE-2025-22226
- EPSS 1.74%
- Veröffentlicht 04.03.2025 12:15:33
- Zuletzt bearbeitet 30.10.2025 19:52:41
- Erkennungen
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Cloud Foundation Version -
VMware ≫ Telco Cloud Infrastructure Version 2.2
VMware ≫ Telco Cloud Infrastructure Version 2.5
VMware ≫ Telco Cloud Infrastructure Version 2.7
VMware ≫ Telco Cloud Infrastructure Version 3.0
VMware ≫ Telco Cloud Platform Version 2.0
VMware ≫ Telco Cloud Platform Version 2.5
VMware ≫ Telco Cloud Platform Version 2.7
VMware ≫ Telco Cloud Platform Version 3.0
VMware ≫ Telco Cloud Platform Version 4.0
VMware ≫ Telco Cloud Platform Version 4.0.1
VMware ≫ Telco Cloud Platform Version 5.0
VMware ≫ Workstation Version >= 17.0 < 17.6.3
04.03.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog
VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability
SchwachstelleVMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.
BeschreibungApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.74% | 0.754 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6 | 1.5 | 4 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
|
| VMware | 7.1 | 2.5 | 4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-22226