CVE-2025-22224
KEVmassTOCTOU Out-of-Bounds Write in VMware ESXi and Workstation Enables Guest-to-Host Escape
CISA: VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
VMware ESXi and Workstation contain a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) that can lead to an out-of-bounds write in the virtual machine's VMX process. To trigger it, a malicious actor needs local administrative privileges inside a guest virtual machine, where the race condition between the host's check and use of a resource can be exploited. Successful exploitation executes code as the VMX process on the host - effectively a guest-to-host escape, since the VMX process runs with host-level privileges on ESXi - reflected in the CVSS 3.1 score of 8.2 with changed scope. Affected products per the available data are VMware ESXi and Workstation, plus VMware Cloud Foundation and VMware Telco Cloud Infrastructure/Platform, which bundle the affected components; specific affected or fixed version ranges are not stated in the provided data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-04, confirming active in-the-wild exploitation (ransomware use is listed as unknown), though no public proof-of-concept code is known.
What to do: Upgrade ESXi, Workstation, VMware Cloud Foundation, and Telco Cloud deployments to the patched releases identified in Broadcom's security advisory (fixed version numbers are not present in the provided data, so confirm them directly in the advisory); because the flaw is on CISA KEV, BOD 22-01-bound organizations must apply vendor mitigations or patches by the KEV deadline or discontinue use of the product. As an interim measure, restrict local administrative privileges inside guest VMs to trusted users only, since guest admin access is the prerequisite for exploitation. Prioritize hosts that are internet-reachable or multi-tenant, where untrusted users are more likely to hold guest admin rights.
| VMware ESXi | — |
| VMware Workstation | — |
| VMware Cloud Foundation | — |
| VMware Telco Cloud Infrastructure | — |
| VMware Telco Cloud Platform | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
- Affected
- VMware ESXi and Workstation
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- vmware
- Products
- esxi, cloud foundation, telco cloud infrastructure, telco cloud platform, workstation
- Weakness
- CWE-367
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H