CVE-2025-22225
published 2025-03-04CVE-2025-22225: VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading…
PriorityP184high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2025-03-25
Exploited in the wild
EPSS
0.96%
57.8th percentile
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | telco_cloud_infrastructure | — | — |
| vmware | telco_cloud_infrastructure | — | — |
| vmware | telco_cloud_infrastructure | — | — |
| vmware | telco_cloud_infrastructure | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandnetsh advfirewall firewall add rule "name=Allow Local Network-2" dir=out action=allow remoteip=10.x.x.x/8 profile=any↗
commandnetsh advfirewall firewall add rule "name=Block External Outbound" dir=out action=block remoteip=0.0.0.0-255.255.255.255 profile=any↗
commandnetsh advfirewall firewall add rule "name=Allow Local Network-3" dir=out action=allow remoteip=172.x.x.x/12 profile=any↗
- →Monitor for the symbolic link \\.\TDLD being created, which indicates MyDriver.sys (the VM escape exploit driver) has been loaded and is polling for exploitation status. ↗
- →Detect disabling of VMware VMCI drivers (PCI\VEN_15AD&DEV_0740 and ROOT\VMWVMCIHOSTDEV) via devcon.exe as a precursor to the VM escape exploit gaining direct hardware access. ↗
- →Monitor for KDU (kdu.exe) execution with '-prv 1 -map' arguments used to load unsigned drivers, bypassing Driver Signature Enforcement as part of the exploit chain. ↗
- →Hunt for PDB paths containing '2024_02_19' or '2023_11_02' folder names and Chinese-language strings (e.g., '全版本逃逸--交付') in binaries on ESXi-adjacent Windows hosts as indicators of this specific toolkit. ↗
- →Detect re-enabling of VMware VMCI drivers immediately after they were disabled, as the exploit restores them post-exploitation for operational security to reduce suspicion. ↗
- ·CVE-2025-22225 requires the attacker to already have privileges within the VMX process; it is typically chained after CVE-2025-22224 (code execution as VMX) and CVE-2025-22226 (memory leak from VMX) to achieve full VM escape. ↗
- ·The exploit toolkit supports 155 ESXi builds spanning versions 5.1 through 8.0; end-of-life versions have no available fix. ↗
- ·Huntress assesses with only moderate confidence that the observed toolkit leverages the three disclosed CVEs; 100% certainty could not be confirmed. ↗
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
vulncheck8.2HIGH
cisa8.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Lifecycle Services with VMware
cisa_ics·2025-03-18·CVSS 9.3
[CRITICAL] Rockwell Automation Lifecycle Services with VMware
ICS Advisory
##
Rockwell Automation Lifecycle Services with VMware
Release DateMarch 18, 2025
Alert CodeICSA-25-077-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Low attack complexity/public exploits are available/known public exploitation
- Vendor: Rockwell Automation
- Equipment: Industrial Data Center (IDC) with VMware, VersaVirtual Appliance (VVA) with VMware, Threat Detection Managed Services (TDMS) with VMware, Endpoint Protection Service with RA Proxy & VMware, Engineered and Integrated Solutions with VMware
- Vulnerabilities: Time-of-check Time-of-use (TOCTOU) Race Condition, Write-what-where Condition, Out-of-bounds Read
## 2. RISK EVALUATION
CISA
VMware ESXi Arbitrary Write Vulnerability
cisa·2025-03-04·CVSS 8.2
CVE-2025-22225 [HIGH] CWE-123 VMware ESXi Arbitrary Write Vulnerability
Vulnerability: VMware ESXi Arbitrary Write Vulnerability
Affected: VMware ESXi
VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390 ; https://nvd.nist.gov/vuln/detail/CVE-2025-22225
Remediation Due Date: 2025-03-25
GHSA
GHSA-2cxw-wgvv-24jj: VMware ESXi contains an arbitrary write vulnerability
ghsa_unreviewed·2025-03-04
CVE-2025-22225 [HIGH] CWE-123 GHSA-2cxw-wgvv-24jj: VMware ESXi contains an arbitrary write vulnerability
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
VulnCheck
VMware ESXi Arbitrary Write Vulnerability
vulncheck·2025·CVSS 8.2
CVE-2025-22225 [HIGH] CWE-123 VMware ESXi Arbitrary Write Vulnerability
VMware ESXi Arbitrary Write Vulnerability
VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.
Affected: VMware ESXi
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabi
No detection rules found.
No public exploits indexed.
Bleepingcomputer
CISA: VMware ESXi flaw now exploited in ransomware attacks
blogs_bleepingcomputer·2026-02-04·CVSS 9.3
CVE-2025-22225 [CRITICAL] CISA: VMware ESXi flaw now exploited in ransomware attacks
## CISA: VMware ESXi flaw now exploited in ransomware attacks
## Sergiu Gatlan
CISA confirmed on Wednesday that ransomware gangs have begun exploiting a high-severity VMware ESXi sandbox escape vulnerability that was used in zero-day attacks since at least February 2024.
Broadcom patched this ESXi arbitrary-write vulnerability (tracked as CVE-2025-22225) almost one year ago, in March 2025, alongside a memory leak (CVE-2025-22226) and a TOCTOU flaw (CVE-2025-22224), and tagged them all as actively exploited zero-days.
"A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox," Broadcom said about the CVE-2025-22225 flaw.
At the time, the company said that the three vulnerabilities affect VMware ESX products, incl
Bleepingcomputer
CISA says critical VMware RCE flaw now actively exploited
blogs_bleepingcomputer·2026-01-26·CVSS 9.8
CVE-2024-37079 [CRITICAL] CISA says critical VMware RCE flaw now actively exploited
## CISA says critical VMware RCE flaw now actively exploited
## Sergiu Gatlan
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a critical VMware vCenter Server vulnerability as actively exploited and ordered federal agencies to secure their servers within three weeks.
Patched in June 2024, this security flaw ( CVE-2024-37079 ) stems from a heap overflow weakness in the DCERPC protocol implementation of vCenter Server (a Broadcom VMware vSphere management platform that helps admins manage ESXi hosts and virtual machines).
Threat actors with network access to vCenter Server may exploit this vulnerability by sending a specially crafted network packet that can trigger remote code execution in low-complexity attacks that don't require privileges on the targeted s
Bleepingcomputer
VMware ESXi zero-days likely exploited a year before disclosure
blogs_bleepingcomputer·2026-01-08·CVSS 9.3
[CRITICAL] VMware ESXi zero-days likely exploited a year before disclosure
## VMware ESXi zero-days likely exploited a year before disclosure
## Bill Toulas
Chinese-speaking threat actors used a compromised SonicWall VPN appliance to deliver a VMware ESXi exploit toolkit that seems to have been developed more than a year before the targeted vulnerabilities became publicly known.
In attacks from December 2025 analyzed by managed security company Huntress, the hackers used a sophisticated virtual machine (VM) escape that likely exploited three VMware vulnerabilities disclosed as zero-days in March 2025.
Of the three bugs, only one received a critical severity score:
CVE-2025-22226 (7.1 severity score): An out-of-bounds read in HGFS that allows leaking memory from the VMX process
CVE-2025-22224 (9.3 severity score): A TOCTOU vulnerability in Virtual Machine Co
Huntress
ESXi Exploitation in the Wild
blogs_huntress·2026-01-07
ESXi Exploitation in the Wild
## Background
In December 2025, Huntress observed an intrusion leading to the deployment of VMware ESXi exploits.
Based on indicators we observed, including the workstation name the threat actor was operating from and other TTPs, the Huntress Tactical Response team assesses with high confidence that initial access occurred via SonicWall VPN.
The toolkit analyzed in this report also includes simplified Chinese strings in its development paths, including a folder named “全版本逃逸--交付” (translated: “All version escape - delivery”), and evidence suggesting it was potentially built as a zero-day exploit over a year before VMware's public disclosure, pointing to a well-resourced developer likely operating in a Chinese-speaking region.
Given the nature of ESXi exploitation, this activity could ha
Bleepingcomputer
CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
blogs_bleepingcomputer·2025-10-30·CVSS 7.8
CVE-2025-41244 [HIGH] CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
## CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
## Sergiu Gatlan
On Thursday, CISA warned U.S. government agencies to secure their systems against attacks exploiting a high-severity vulnerability in Broadcom's VMware Aria Operations and VMware Tools software.
Tracked as CVE-2025-41244 and patched one month ago , this vulnerability allows local attackers with non-administrative privileges to a virtual machine (VM) with VMware Tools and managed by Aria Operations with SDMP enabled to escalate privileges to root on the same VM.
CISA added the flaw to its Known Exploited Vulnerabilities catalog , which lists security bugs the cybersecurity agency has flagged as exploited in the wild. Federal Civilian Executive Branch (FCEB) agencies now have three weeks, until N
Bleepingcomputer
Chinese hackers exploiting VMware zero-day since October 2024
blogs_bleepingcomputer·2025-09-30·CVSS 9.8
CVE-2025-41244 [CRITICAL] Chinese hackers exploiting VMware zero-day since October 2024
## Chinese hackers exploiting VMware zero-day since October 2024
## Sergiu Gatlan
Broadcom has patched a high-severity privilege escalation vulnerability in its VMware Aria Operations and VMware Tools software, which has been exploited in zero-day attacks since October 2024.
While the American technology giant didn't tag this security bug ( CVE-2025-41244 ) as exploited in the wild, it thanked NVISO threat researcher Maxime Thiebaut for reporting the bug in May.
However, yesterday, the European cybersecurity company disclosed that this vulnerability was first exploited in the wild beginning mid-October 2024 and linked the attacks to the UNC5174 Chinese state-sponsored threat actor.
"To abuse this vulnerability, an unprivileged local attacker can stage a malicious binary within any of
Bleepingcomputer
Broadcom fixes high-severity VMware NSX bugs reported by NSA
blogs_bleepingcomputer·2025-09-30·CVSS 9.3
CVE-2025-41251 [CRITICAL] Broadcom fixes high-severity VMware NSX bugs reported by NSA
## Broadcom fixes high-severity VMware NSX bugs reported by NSA
## Sergiu Gatlan
Broadcom has released security updates to patch two high-severity VMware NSX vulnerabilities reported by the U.S. National Security Agency (NSA).
VMware NSX is a networking virtualization solution within VMware Cloud Foundation that enables administrators to deploy traditional and modern applications in private/hybrid clouds.
The first security flaw reported by the NSA, tracked as CVE-2025-41251 , is due to a weakness in the password recovery mechanism that can let unauthenticated attackers enumerate valid usernames, which could later be used in brute-force attacks.
The second one ( CVE-2025-41252 ) is a username enumeration vulnerability that unauthenticated threat actors can also exploit to enumerate va
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
#### Table of Contents
- Who is LockBit? How it Evolved and Operates
- Monero: The Coin of the Realm
- Patch or Mitigate Now: Critical CVEs Exploited by LockBit
- Beyond Traditional Endpoints: Other Compromised Systems
- Initial Access and Deployment
- Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Wiz
Crying Out Cloud Newsletter - April 2025 | Wiz
blogs_wiz·2025-04-01·CVSS 9.8
CVE-2025-24813 [CRITICAL] Crying Out Cloud Newsletter - April 2025 | Wiz
Welcome back! In this edition, we bring you the latest in cloud security – noteworthy incidents, exclusive data, and crucial vulnerabilities. Let's dive in.
Here are our top picks of cloud security highlights!
Hype or no hype - RCE Vulnerability in Apache Tomcat Exploited in-the-Wild
CVE-2025-24813 is a remote code execution (RCE) vulnerability affecting Apache Tomcat. Under specific conditions, an attacker can upload a malicious session file via a partial PUT request and trigger its execution, potentially leading to full server compromise. The exploit requires several preconditions to be met, including specific server configurations and the presence of a deserialization-vulnerable library. While active exploitation has reportedly been observed in the wild, we estimate that in practice,
Tenable
Cybersecurity Snapshot: CSA Outlines Data Security Challenges and Best Practices, While ISACA Offers Tips To Retain IT Pros
blogs_tenable·2025-03-07
Cybersecurity Snapshot: CSA Outlines Data Security Challenges and Best Practices, While ISACA Offers Tips To Retain IT Pros
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Over 37,000 VMware ESXi servers vulnerable to ongoing attacks
blogs_bleepingcomputer·2025-03-06·CVSS 9.3
CVE-2025-22224 [CRITICAL] Over 37,000 VMware ESXi servers vulnerable to ongoing attacks
## Over 37,000 VMware ESXi servers vulnerable to ongoing attacks
## Bill Toulas
Over 37,000 internet-exposed VMware ESXi instances are vulnerable to CVE-2025-22224, a critical out-of-bounds write flaw that is actively exploited in the wild.
This massive exposure is being reported by threat monitoring platform The Shadowserver Foundation, which reported a figure of around 41,500 yesterday.
Today, ShadowServer now reports that 37,000 are still vulnerable, indicating that 4,500 devices were patched yesterday.
CVE-2025-22224 is a critical-severity VCMI heap overflow vulnerability that enables local attackers with administrative privileges on the VM guest to escape the sandbox and execute code on the host as the VMX process.
Broadcom warned customers about it along with two other flaws, C
Bleepingcomputer
Broadcom fixes three VMware zero-days exploited in attacks
blogs_bleepingcomputer·2025-03-04·CVSS 9.8
CVE-2025-22224 [CRITICAL] Broadcom fixes three VMware zero-days exploited in attacks
## Broadcom fixes three VMware zero-days exploited in attacks
## Sergiu Gatlan
"This is a situation where an attacker who has already compromised a virtual machine's guest OS and gained privileged access (administrator or root) could move into the hypervisor itself," the company explained today. "Broadcom has information to suggest that exploitation of these issues has occurred 'in the wild'."
Broadcom says CVE-2025-22224 is a critical-severity VCMI heap overflow vulnerability that enables local attackers with administrative privileges on the targeted VM to execute code as the VMX process running on the host.
CVE-2025-22225 is an ESXi arbitrary write vulnerability that allows the VMX process to trigger arbitrary kernel writes, leading to a sandbox escape, while CVE-2025-22226 is descri
Tenable
CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Zero-Day Vulnerabilities in VMware ESXi, Workstation and Fusion Exploited
blogs_tenable·2025-03-04·CVSS 9.3
[CRITICAL] CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Zero-Day Vulnerabilities in VMware ESXi, Workstation and Fusion Exploited
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Huntress
ESXi Exploitation in the Wild | Huntress
blogs_huntress
ESXi Exploitation in the Wild | Huntress
## Background
In December 2025, Huntress observed an intrusion leading to the deployment of VMware ESXi exploits.
Based on indicators we observed, including the workstation name the threat actor was operating from and other TTPs, the Huntress Tactical Response team assesses with high confidence that initial access occurred via SonicWall VPN.
The toolkit analyzed in this report also includes simplified Chinese strings in its development paths, including a folder named “全版本逃逸--交付” (translated: “All version escape - delivery”), and evidence suggesting it was potentially built as a zero-day exploit over a year before VMware's public disclosure, pointing to a well-resourced developer likely operating in a Chinese-speaking region.
Given the nature of ESXi exploitation, this activity could ha
2025-03-04
Published
2025-03-04
Added to CISA KEV
Exploited in the wild