CVE-2025-22224
04.03.2025, 12:15
VMware ESXi, and Workstationcontain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write.A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
| Vendor | Product | Version |
|---|---|---|
| vmware | esxi | 7.0 |
| vmware | esxi | 7.0:beta |
| vmware | esxi | 7.0:update_1 |
| vmware | esxi | 7.0:update_1a |
| vmware | esxi | 7.0:update_1b |
| vmware | esxi | 7.0:update_1c |
| vmware | esxi | 7.0:update_1d |
| vmware | esxi | 7.0:update_1e |
| vmware | esxi | 7.0:update_2 |
| vmware | esxi | 7.0:update_2a |
| vmware | esxi | 7.0:update_2c |
| vmware | esxi | 7.0:update_2d |
| vmware | esxi | 7.0:update_2e |
| vmware | esxi | 7.0:update_3 |
| vmware | esxi | 7.0:update_3c |
| vmware | esxi | 7.0:update_3d |
| vmware | esxi | 7.0:update_3e |
| vmware | esxi | 7.0:update_3f |
| vmware | esxi | 7.0:update_3g |
| vmware | esxi | 7.0:update_3i |
| vmware | esxi | 7.0:update_3j |
| vmware | esxi | 7.0:update_3k |
| vmware | esxi | 7.0:update_3l |
| vmware | esxi | 7.0:update_3m |
| vmware | esxi | 7.0:update_3n |
| vmware | esxi | 7.0:update_3o |
| vmware | esxi | 7.0:update_3p |
| vmware | esxi | 7.0:update_3q |
| vmware | esxi | 7.0:update_3r |
| vmware | esxi | 8.0 |
| vmware | esxi | 8.0:a |
| vmware | esxi | 8.0:b |
| vmware | esxi | 8.0:c |
| vmware | esxi | 8.0:update_1 |
| vmware | esxi | 8.0:update_1a |
| vmware | esxi | 8.0:update_1c |
| vmware | esxi | 8.0:update_1d |
| vmware | esxi | 8.0:update_2 |
| vmware | esxi | 8.0:update_2b |
| vmware | esxi | 8.0:update_2c |
| vmware | esxi | 8.0:update_3 |
| vmware | esxi | 8.0:update_3b |
| vmware | esxi | 8.0:update_3c |
| vmware | cloud_foundation | - |
| vmware | telco_cloud_infrastructure | 2.2 |
| vmware | telco_cloud_infrastructure | 2.5 |
| vmware | telco_cloud_infrastructure | 2.7 |
| vmware | telco_cloud_infrastructure | 3.0 |
| vmware | telco_cloud_platform | 2.0 |
| vmware | telco_cloud_platform | 2.5 |
| vmware | telco_cloud_platform | 2.7 |
| vmware | telco_cloud_platform | 3.0 |
| vmware | telco_cloud_platform | 4.0 |
| vmware | telco_cloud_platform | 4.0.1 |
| vmware | telco_cloud_platform | 5.0 |
| vmware | workstation | 17.0 ≤ 𝑥 < 17.6.3 |
𝑥
= Vulnerable software versions