CVE-2025-22224
published 2025-03-04CVE-2025-22224: VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local…
PriorityP185high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2025-03-25
Exploited in the wild
EPSS
1.52%
71.8th percentile
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | >= 7.0 < ESXi70U3s-24585291 | ESXi70U3s-24585291 |
| vmware | esxi | >= 8.0 < ESXi80U3d-24585383 | ESXi80U3d-24585383 |
| vmware | esxi | >= 8.0 < ESXi80U2d-24585300 | ESXi80U2d-24585300 |
| vmware | telco_cloud_infrastructure | — | — |
| vmware | telco_cloud_infrastructure | — | — |
| vmware | telco_cloud_infrastructure | — | — |
| vmware | telco_cloud_infrastructure | — | — |
| vmware | telco_cloud_infrastructure | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | vmware_cloud_foundation | — | — |
| vmware | workstation | >= 17.0 < 17.6.3 | 17.6.3 |
| vmware | workstation | >= 17.x < 17.6.3 | 17.6.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect loading of known vulnerable signed drivers via KDU (Kernel Driver Utility) to identify BYOD/DSE-bypass techniques used to load unsigned exploit drivers. ↗
- →Hunt for the symbolic link device object \\.\TDLD being created or opened, which is used by MyDriver.sys to communicate exploit status back to the orchestrator. ↗
- →Detect Windows firewall rule additions that block all external outbound traffic while allowing RFC-1918 ranges, a pattern used to isolate victims during this intrusion. ↗
- →Look for PDB paths containing '2024_02_19' or '2023_11_02' and folder names with simplified Chinese characters (全版本逃逸--交付) in memory or on disk as indicators of this specific toolkit. ↗
- →The exploit toolkit supports 155 ESXi builds spanning versions 5.1 through 8.0; prioritize detection on end-of-life ESXi versions that cannot be patched. ↗
- ·No workarounds exist for CVE-2025-22224; patching is the only remediation path. ↗
- ·The exploit chain requires an attacker to already have local administrative privileges on a guest VM before CVE-2025-22224 can be exploited. ↗
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
vulncheck9.3CRITICAL
cisa8.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Lifecycle Services with VMware
cisa_ics·2025-03-18·CVSS 9.3
[CRITICAL] Rockwell Automation Lifecycle Services with VMware
ICS Advisory
##
Rockwell Automation Lifecycle Services with VMware
Release DateMarch 18, 2025
Alert CodeICSA-25-077-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Low attack complexity/public exploits are available/known public exploitation
- Vendor: Rockwell Automation
- Equipment: Industrial Data Center (IDC) with VMware, VersaVirtual Appliance (VVA) with VMware, Threat Detection Managed Services (TDMS) with VMware, Endpoint Protection Service with RA Proxy & VMware, Engineered and Integrated Solutions with VMware
- Vulnerabilities: Time-of-check Time-of-use (TOCTOU) Race Condition, Write-what-where Condition, Out-of-bounds Read
## 2. RISK EVALUATION
CISA
VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
cisa·2025-03-04·CVSS 8.2
CVE-2025-22224 [HIGH] CWE-367 VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
Vulnerability: VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
Affected: VMware ESXi and Workstation
VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390 ; https://nvd.nist.gov/vuln/detail/CVE-2025-22224
Remediation
GHSA
GHSA-j652-46fv-w96g: VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write
ghsa_unreviewed·2025-03-04
CVE-2025-22224 [CRITICAL] CWE-367 GHSA-j652-46fv-w96g: VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
VulnCheck
VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
vulncheck·2025·CVSS 9.3
CVE-2025-22224 [CRITICAL] CWE-367 VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.
Affected: VMware ESXi and Workstation
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390; https://www.cisa.go
No detection rules found.
No public exploits indexed.
Bleepingcomputer
CISA: VMware ESXi flaw now exploited in ransomware attacks
blogs_bleepingcomputer·2026-02-04·CVSS 9.3
CVE-2025-22225 [CRITICAL] CISA: VMware ESXi flaw now exploited in ransomware attacks
## CISA: VMware ESXi flaw now exploited in ransomware attacks
## Sergiu Gatlan
CISA confirmed on Wednesday that ransomware gangs have begun exploiting a high-severity VMware ESXi sandbox escape vulnerability that was used in zero-day attacks since at least February 2024.
Broadcom patched this ESXi arbitrary-write vulnerability (tracked as CVE-2025-22225) almost one year ago, in March 2025, alongside a memory leak (CVE-2025-22226) and a TOCTOU flaw (CVE-2025-22224), and tagged them all as actively exploited zero-days.
"A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox," Broadcom said about the CVE-2025-22225 flaw.
At the time, the company said that the three vulnerabilities affect VMware ESX products, incl
Bleepingcomputer
CISA says critical VMware RCE flaw now actively exploited
blogs_bleepingcomputer·2026-01-26·CVSS 9.8
CVE-2024-37079 [CRITICAL] CISA says critical VMware RCE flaw now actively exploited
## CISA says critical VMware RCE flaw now actively exploited
## Sergiu Gatlan
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a critical VMware vCenter Server vulnerability as actively exploited and ordered federal agencies to secure their servers within three weeks.
Patched in June 2024, this security flaw ( CVE-2024-37079 ) stems from a heap overflow weakness in the DCERPC protocol implementation of vCenter Server (a Broadcom VMware vSphere management platform that helps admins manage ESXi hosts and virtual machines).
Threat actors with network access to vCenter Server may exploit this vulnerability by sending a specially crafted network packet that can trigger remote code execution in low-complexity attacks that don't require privileges on the targeted s
Bleepingcomputer
VMware ESXi zero-days likely exploited a year before disclosure
blogs_bleepingcomputer·2026-01-08·CVSS 9.3
[CRITICAL] VMware ESXi zero-days likely exploited a year before disclosure
## VMware ESXi zero-days likely exploited a year before disclosure
## Bill Toulas
Chinese-speaking threat actors used a compromised SonicWall VPN appliance to deliver a VMware ESXi exploit toolkit that seems to have been developed more than a year before the targeted vulnerabilities became publicly known.
In attacks from December 2025 analyzed by managed security company Huntress, the hackers used a sophisticated virtual machine (VM) escape that likely exploited three VMware vulnerabilities disclosed as zero-days in March 2025.
Of the three bugs, only one received a critical severity score:
CVE-2025-22226 (7.1 severity score): An out-of-bounds read in HGFS that allows leaking memory from the VMX process
CVE-2025-22224 (9.3 severity score): A TOCTOU vulnerability in Virtual Machine Co
Huntress
ESXi Exploitation in the Wild
blogs_huntress·2026-01-07
ESXi Exploitation in the Wild
## Background
In December 2025, Huntress observed an intrusion leading to the deployment of VMware ESXi exploits.
Based on indicators we observed, including the workstation name the threat actor was operating from and other TTPs, the Huntress Tactical Response team assesses with high confidence that initial access occurred via SonicWall VPN.
The toolkit analyzed in this report also includes simplified Chinese strings in its development paths, including a folder named “全版本逃逸--交付” (translated: “All version escape - delivery”), and evidence suggesting it was potentially built as a zero-day exploit over a year before VMware's public disclosure, pointing to a well-resourced developer likely operating in a Chinese-speaking region.
Given the nature of ESXi exploitation, this activity could ha
Bleepingcomputer
CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
blogs_bleepingcomputer·2025-10-30·CVSS 7.8
CVE-2025-41244 [HIGH] CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
## CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
## Sergiu Gatlan
On Thursday, CISA warned U.S. government agencies to secure their systems against attacks exploiting a high-severity vulnerability in Broadcom's VMware Aria Operations and VMware Tools software.
Tracked as CVE-2025-41244 and patched one month ago , this vulnerability allows local attackers with non-administrative privileges to a virtual machine (VM) with VMware Tools and managed by Aria Operations with SDMP enabled to escalate privileges to root on the same VM.
CISA added the flaw to its Known Exploited Vulnerabilities catalog , which lists security bugs the cybersecurity agency has flagged as exploited in the wild. Federal Civilian Executive Branch (FCEB) agencies now have three weeks, until N
Bleepingcomputer
Chinese hackers exploiting VMware zero-day since October 2024
blogs_bleepingcomputer·2025-09-30·CVSS 9.8
CVE-2025-41244 [CRITICAL] Chinese hackers exploiting VMware zero-day since October 2024
## Chinese hackers exploiting VMware zero-day since October 2024
## Sergiu Gatlan
Broadcom has patched a high-severity privilege escalation vulnerability in its VMware Aria Operations and VMware Tools software, which has been exploited in zero-day attacks since October 2024.
While the American technology giant didn't tag this security bug ( CVE-2025-41244 ) as exploited in the wild, it thanked NVISO threat researcher Maxime Thiebaut for reporting the bug in May.
However, yesterday, the European cybersecurity company disclosed that this vulnerability was first exploited in the wild beginning mid-October 2024 and linked the attacks to the UNC5174 Chinese state-sponsored threat actor.
"To abuse this vulnerability, an unprivileged local attacker can stage a malicious binary within any of
Bleepingcomputer
Broadcom fixes high-severity VMware NSX bugs reported by NSA
blogs_bleepingcomputer·2025-09-30·CVSS 9.3
CVE-2025-41251 [CRITICAL] Broadcom fixes high-severity VMware NSX bugs reported by NSA
## Broadcom fixes high-severity VMware NSX bugs reported by NSA
## Sergiu Gatlan
Broadcom has released security updates to patch two high-severity VMware NSX vulnerabilities reported by the U.S. National Security Agency (NSA).
VMware NSX is a networking virtualization solution within VMware Cloud Foundation that enables administrators to deploy traditional and modern applications in private/hybrid clouds.
The first security flaw reported by the NSA, tracked as CVE-2025-41251 , is due to a weakness in the password recovery mechanism that can let unauthenticated attackers enumerate valid usernames, which could later be used in brute-force attacks.
The second one ( CVE-2025-41252 ) is a username enumeration vulnerability that unauthenticated threat actors can also exploit to enumerate va
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
#### Table of Contents
- Who is LockBit? How it Evolved and Operates
- Monero: The Coin of the Realm
- Patch or Mitigate Now: Critical CVEs Exploited by LockBit
- Beyond Traditional Endpoints: Other Compromised Systems
- Initial Access and Deployment
- Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Wiz
Crying Out Cloud Newsletter - April 2025 | Wiz
blogs_wiz·2025-04-01·CVSS 9.8
CVE-2025-24813 [CRITICAL] Crying Out Cloud Newsletter - April 2025 | Wiz
Welcome back! In this edition, we bring you the latest in cloud security – noteworthy incidents, exclusive data, and crucial vulnerabilities. Let's dive in.
Here are our top picks of cloud security highlights!
Hype or no hype - RCE Vulnerability in Apache Tomcat Exploited in-the-Wild
CVE-2025-24813 is a remote code execution (RCE) vulnerability affecting Apache Tomcat. Under specific conditions, an attacker can upload a malicious session file via a partial PUT request and trigger its execution, potentially leading to full server compromise. The exploit requires several preconditions to be met, including specific server configurations and the presence of a deserialization-vulnerable library. While active exploitation has reportedly been observed in the wild, we estimate that in practice,
Talos
Patch it up: Old vulnerabilities are everyone’s problems
blogs_talos·2025-03-13·CVSS 9.3
[CRITICAL] Patch it up: Old vulnerabilities are everyone’s problems
## Patch it up: Old vulnerabilities are everyone’s problems
Welcome to this week’s edition of the Threat Source newsletter.
Let's pick up where we left off in my last newsletter. Please mark your calendars: The free support for Windows 10 will end on October 14, 2025.
When a software loses vendor support, it no longer receives patches or updates. As highlighted in my previous newsletter, the top method for initial access in the last quarter of 2024 was exploiting vulnerabilities in public-facing applications. While Windows 10 isn't typically (or shouldn't be) a public-facing application, unpatched client systems become prime targets for bad actors as they progress through the stages of an attack: Execution, Privilege Escalation, Defense Evasion, Credential Access, and Lateral Movement.
Talos
Patch it up: Old vulnerabilities are everyone’s problems
blogs_talos·2025-03-13·CVSS 9.3
[CRITICAL] Patch it up: Old vulnerabilities are everyone’s problems
Welcome to this week’s edition of the Threat Source newsletter.
Let's pick up where we left off in my last newsletter. Please mark your calendars: The free support for Windows 10 will end on October 14, 2025.
When a software loses vendor support, it no longer receives patches or updates. As highlighted in my previous newsletter, the top method for initial access in the last quarter of 2024 was exploiting vulnerabilities in public-facing applications. While Windows 10 isn't typically (or shouldn't be) a public-facing application, unpatched client systems become prime targets for bad actors as they progress through the stages of an attack: Execution, Privilege Escalation, Defense Evasion, Credential Access, and Lateral Movement.
In last week’s newsletter, my colleague Martin asked, "Who i
Checkpoint
10th March – Threat Intelligence Report
blogs_checkpoint·2025-03-10
CVE-2025-22224 10th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 10th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th March, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The City of Mission, Texas, has declared a local state of emergency following a severe cybersecurity incident that threatens to expose protected personal information, health records, and other critical data managed by city departments. The emergency declaration was issued by Mayor Norie Gonzalez Garza on March 4, 2025, after
Tenable
Cybersecurity Snapshot: CSA Outlines Data Security Challenges and Best Practices, While ISACA Offers Tips To Retain IT Pros
blogs_tenable·2025-03-07
Cybersecurity Snapshot: CSA Outlines Data Security Challenges and Best Practices, While ISACA Offers Tips To Retain IT Pros
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Over 37,000 VMware ESXi servers vulnerable to ongoing attacks
blogs_bleepingcomputer·2025-03-06·CVSS 9.3
CVE-2025-22224 [CRITICAL] Over 37,000 VMware ESXi servers vulnerable to ongoing attacks
## Over 37,000 VMware ESXi servers vulnerable to ongoing attacks
## Bill Toulas
Over 37,000 internet-exposed VMware ESXi instances are vulnerable to CVE-2025-22224, a critical out-of-bounds write flaw that is actively exploited in the wild.
This massive exposure is being reported by threat monitoring platform The Shadowserver Foundation, which reported a figure of around 41,500 yesterday.
Today, ShadowServer now reports that 37,000 are still vulnerable, indicating that 4,500 devices were patched yesterday.
CVE-2025-22224 is a critical-severity VCMI heap overflow vulnerability that enables local attackers with administrative privileges on the VM guest to escape the sandbox and execute code on the host as the VMX process.
Broadcom warned customers about it along with two other flaws, C
Bleepingcomputer
Broadcom fixes three VMware zero-days exploited in attacks
blogs_bleepingcomputer·2025-03-04·CVSS 9.8
CVE-2025-22224 [CRITICAL] Broadcom fixes three VMware zero-days exploited in attacks
## Broadcom fixes three VMware zero-days exploited in attacks
## Sergiu Gatlan
"This is a situation where an attacker who has already compromised a virtual machine's guest OS and gained privileged access (administrator or root) could move into the hypervisor itself," the company explained today. "Broadcom has information to suggest that exploitation of these issues has occurred 'in the wild'."
Broadcom says CVE-2025-22224 is a critical-severity VCMI heap overflow vulnerability that enables local attackers with administrative privileges on the targeted VM to execute code as the VMX process running on the host.
CVE-2025-22225 is an ESXi arbitrary write vulnerability that allows the VMX process to trigger arbitrary kernel writes, leading to a sandbox escape, while CVE-2025-22226 is descri
Tenable
CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Zero-Day Vulnerabilities in VMware ESXi, Workstation and Fusion Exploited
blogs_tenable·2025-03-04·CVSS 9.3
[CRITICAL] CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Zero-Day Vulnerabilities in VMware ESXi, Workstation and Fusion Exploited
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Huntress
ESXi Exploitation in the Wild | Huntress
blogs_huntress
ESXi Exploitation in the Wild | Huntress
## Background
In December 2025, Huntress observed an intrusion leading to the deployment of VMware ESXi exploits.
Based on indicators we observed, including the workstation name the threat actor was operating from and other TTPs, the Huntress Tactical Response team assesses with high confidence that initial access occurred via SonicWall VPN.
The toolkit analyzed in this report also includes simplified Chinese strings in its development paths, including a folder named “全版本逃逸--交付” (translated: “All version escape - delivery”), and evidence suggesting it was potentially built as a zero-day exploit over a year before VMware's public disclosure, pointing to a well-resourced developer likely operating in a Chinese-speaking region.
Given the nature of ESXi exploitation, this activity could ha
2025-03-04
Published
2025-03-04
Added to CISA KEV
Exploited in the wild