Cyber Security News

CISA Warns of Actively Exploited VMware Vulnerabilities, Urges Immediate Patching

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert on March 4, 2025, adding three critical VMware vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog following confirmed in-the-wild exploitation.

The vulnerabilities CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 allow attackers with privileged access to virtual machines (VMs) to escalate privileges, execute code on hypervisors, and exfiltrate sensitive memory data.

These flaws, discovered by Microsoft Threat Intelligence Center (MSTIC), affect VMware ESXi, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform products.

CISA’s advisory coincides with Broadcom’s release of patches, emphasizing the need for federal agencies and private organizations to prioritize remediation under the Binding Operational Directive (BOD).

VMware Vulnerabilities Exploited

Critical TOCTOU Flaw Enables Hypervisor Takeover (CVE-2025-22224)

CVE-2025-22224, the most severe of the trio with a CVSS score of 9.3, is a Time-of-Check Time-of-Use (TOCTOU) race condition in VMware ESXi and Workstation.

Attackers with administrative privileges on a VM can exploit this heap overflow vulnerability to execute arbitrary code within the VMX process—the hypervisor component managing VM operations.

Successful exploitation grants control over the host system, enabling lateral movement across virtualized infrastructures.

Sandbox Escape via Arbitrary Write (CVE-2025-22225)

CVE-2025-22225 (CVSS 8.2) permits authenticated attackers to write arbitrary data to ESXi hosts through the VMX process, facilitating sandbox escapes. By manipulating kernel memory, adversaries gain elevated privileges to deploy malware or disrupt services.

This flaw is particularly dangerous in multi-tenant cloud environments, where a single compromised VM could jeopardize entire clusters.

Hypervisor Memory Leakage (CVE-2025-22226)

The third vulnerability, CVE-2025-22226 (CVSS 7.1), stems from an out-of-bounds read in VMware’s Host Guest File System (HGFS).

Attackers leveraging this flaw can extract sensitive data from the VMX process, including encryption keys or credentials stored in hypervisor memory. While less severe than the others, it provides critical reconnaissance data for orchestrating further attacks.

Broadcom released fixes for all affected products, including:

  • ESXi 8.0/7.0: Patches ESXi80U3d-24585383 and ESXi70U3s-24585291
  • Workstation 17.x: Version 17.6.3 addresses CVE-2025-22224/22226
  • Fusion 13.x: Update 13.6.3 resolves CVE-2025-22226

Organizations using VMware Cloud Foundation or Telco Cloud Platform must apply asynchronous patches or upgrade to fixed ESXi versions.

  1. Immediate Patching: Prioritize updates for ESXi, Workstation, and Fusion.
  2. Monitor VM Activity: Detect unusual privilege escalation or memory access patterns.
  3. Leverage BOD 22-01 Frameworks: Align remediation workflows with CISA’s KEV timelines.

With exploitation already observed, delayed patching risks large-scale breaches akin to the 2024 vCenter Server incidents. As virtualization underpins critical infrastructure, proactive defense is paramount to thwarting nation-state adversaries seeking persistent access.

Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago