Vulnerability identifier: #VU105278
Vulnerability risk: High
CVSSv4.0: 6.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/U:Amber]
CVE-ID: CVE-2025-22224
CWE-ID:
CWE-122
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
VMware ESXi
Operating systems & Components /
Operating system
Vendor: VMware, Inc
Description
The vulnerability allows a malicious guest to execute arbitrary code on the hypervisor.
The vulnerability exists due to a boundary error in VMCI. A malicious guest with administrative privileges can trigger a heap-based buffer overflow and execute arbitrary code on the hypervisor in the context of VMX process.
Note, the vulnerability is being actively exploited in the wild.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
VMware ESXi: ESXi 6.7 P06 - 8.0
External links
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
Yes. This vulnerability is being exploited in the wild.