cbcvebase.
CVE-2025-22225
published 2025-03-04

CVE-2025-22225: VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading…

high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
KEV
CISA Known Exploited Vulnerabilitydue 2025-03-25
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

Affected

13 ranges
VendorProductVersion rangeFixed in
vmwareesxi
vmwareesxi
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_infrastructure
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
vulncheck8.2HIGH
cisa8.2HIGH