Vmware Esxi vulnerabilities
146 known vulnerabilities affecting vmware/esxi.
Total CVEs
146
CISA KEV
8
actively exploited
Public exploits
17
Exploited in wild
16
Severity breakdown
CRITICAL19HIGH59MEDIUM62LOW6
Vulnerabilities
Page 1 of 8
CVE-2019-5544P1CRITICALCVSS 9.8KEVPoCRansomwarev6.0v6.5+1 more2019-12-06
CVE-2019-5544 [CRITICAL] CWE-787 CVE-2019-5544: OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evalu
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
nvd
CVE-2020-3992P1CRITICALCVSS 9.8KEVPoCRansomwarev6.5v6.7+1 more2020-10-20
CVE-2020-3992 [CRITICAL] CWE-416 CVE-2020-3992: OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG,
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code ex
nvd
CVE-2023-29552P1HIGHCVSS 7.5KEVPoCRansomwarefixed in 7.02023-04-25
CVE-2023-29552 [HIGH] CVE-2023-29552: The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
nvd
CVE-2010-3904P1HIGHCVSS 7.8KEVPoCv3.5v4.0+2 more2010-12-06
CVE-2010-3904 [HIGH] CWE-1284 CVE-2010-3904: The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol im
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
nvd
CVE-2024-37085P1HIGHCVSS 7.2KEVRansomwarev7.0v8.02024-06-25
CVE-2024-37085 [HIGH] CWE-287 CVE-2024-37085: VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Activ
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group
nvd
CVE-2025-22224P1HIGHCVSS 8.2KEVRansomwarev7.0v8.0+3 more2025-03-04
CVE-2025-22224 [HIGH] CWE-367 CVE-2025-22224: VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads t
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
nvd
CVE-2025-22225P1HIGHCVSS 8.2KEVRansomwarev7.0v8.02025-03-04
CVE-2025-22225 [HIGH] CWE-787 CVE-2025-22225: VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
nvd
CVE-2025-22226P1MEDIUMCVSS 6.0KEVRansomwarev7.0v8.0+3 more2025-03-04
CVE-2025-22226 [MEDIUM] CWE-125 CVE-2025-22226: VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-o
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
nvd
CVE-2021-21974P1HIGHCVSS 8.8ExploitedPoCRansomwarev6.5v6.7+1 more2021-02-24
CVE-2021-21974 [HIGH] CWE-787 CVE-2021-21974: OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.
nvd
CVE-2009-3733P2MEDIUMCVSS 5.0ExploitedPoCv3.52009-11-02
CVE-2009-3733 [MEDIUM] CWE-22 CVE-2009-3733: Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors.
nvd
CVE-2009-2267P2MEDIUMCVSS 6.9ExploitedPoCv3.5v4.02009-11-02
CVE-2009-2267 [MEDIUM] CVE-2009-2267: VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, V
VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is
nvd
CVE-2009-2698P2HIGHCVSS 7.8ExploitedPoCv4.02009-08-27
CVE-2009-2698 [HIGH] CWE-476 CVE-2009-2698: The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in t
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.
nvd
CVE-2024-22255P1HIGHCVSS 7.1ExploitedRansomwarev7.0v7.0.0+1 more2024-03-05
CVE-2024-22255 [HIGH] CWE-770 CVE-2024-22255: VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
nvd
CVE-2024-22254P1HIGHCVSS 8.2ExploitedRansomwarev7.0v7.0.0+1 more2024-03-05
CVE-2024-22254 [HIGH] CWE-787 CVE-2024-22254: VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.
nvd
CVE-2024-22253P1MEDIUMCVSS 6.7ExploitedRansomwarev7.0v7.0.0+1 more2024-03-05
CVE-2024-22253 [MEDIUM] CWE-416 CVE-2024-22253: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controll
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on
nvd
CVE-2024-22252P1MEDIUMCVSS 6.7ExploitedRansomwarev7.0v7.0.0+1 more2024-03-05
CVE-2024-22252 [MEDIUM] CWE-416 CVE-2024-22252: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controll
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on
nvd
CVE-2017-5753P2MEDIUMCVSS 5.6PoCv5.5.0v6.0+1 more2018-01-04
CVE-2017-5753 [MEDIUM] CWE-203 CVE-2017-5753: Systems with microprocessors utilizing speculative execution and branch prediction may allow unautho
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
nvd
CVE-2010-0211P2CRITICALCVSS 9.8PoCv4.0v4.12010-07-28
CVE-2010-0211 [CRITICAL] CWE-252 CVE-2010-0211: The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a ca
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an
nvd
CVE-2016-5330P3HIGHCVSS 7.8PoC≥ 5.0, ≤ 6.02016-08-08
CVE-2016-5330 [HIGH] CWE-426 CVE-2016-5330: Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x before 8.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
nvd
CVE-2021-21994P2CRITICALCVSS 9.8v6.5v6.7+1 more2021-07-13
CVE-2021-21994 [CRITICAL] CWE-287 CVE-2021-21994: SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A mali
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.
nvd
1 / 8Next →