cbcvebase.
CVE-2025-22224
published 2025-03-04

CVE-2025-22224: VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local…

PriorityP185high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2025-03-25
Exploited in the wild
EPSS
1.52%
71.8th percentile
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

Affected

21 ranges
VendorProductVersion rangeFixed in
vmwareesxi
vmwareesxi
vmwareesxi>= 7.0 < ESXi70U3s-24585291ESXi70U3s-24585291
vmwareesxi>= 8.0 < ESXi80U3d-24585383ESXi80U3d-24585383
vmwareesxi>= 8.0 < ESXi80U2d-24585300ESXi80U2d-24585300
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwarevmware_cloud_foundation
vmwareworkstation>= 17.0 < 17.6.317.6.3
vmwareworkstation>= 17.x < 17.6.317.6.3

Detection & IOCsextracted from sources · hover to see the quote

filenameexploit.exe
filenameMyDriver.sys
filenamekdu.exe
filenamedevcon.exe
filenamedrv64.dll
filenameclient.exe
pathC:\Users\\Downloads\Advanced_Port_Scanner_2.5.3869.exe
pathC:\Program Files\SoftPerfect Network Scanner\netscan.exe
pathC:\ProgramData\shares.txt
other\\.\TDLD
commandkdu.exe -prv 1 -map MyDriver.sys
  • Detect loading of known vulnerable signed drivers via KDU (Kernel Driver Utility) to identify BYOD/DSE-bypass techniques used to load unsigned exploit drivers.
  • Hunt for the symbolic link device object \\.\TDLD being created or opened, which is used by MyDriver.sys to communicate exploit status back to the orchestrator.
  • Detect Windows firewall rule additions that block all external outbound traffic while allowing RFC-1918 ranges, a pattern used to isolate victims during this intrusion.
  • Look for PDB paths containing '2024_02_19' or '2023_11_02' and folder names with simplified Chinese characters (全版本逃逸--交付) in memory or on disk as indicators of this specific toolkit.
  • The exploit toolkit supports 155 ESXi builds spanning versions 5.1 through 8.0; prioritize detection on end-of-life ESXi versions that cannot be patched.
  • ·No workarounds exist for CVE-2025-22224; patching is the only remediation path.
  • ·The exploit chain requires an attacker to already have local administrative privileges on a guest VM before CVE-2025-22224 can be exploited.

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
vulncheck9.3CRITICAL
cisa8.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.