ZeroHour

CVE-2025-22224

KEVmass

TOCTOU Out-of-Bounds Write in VMware ESXi and Workstation Enables Guest-to-Host Escape

CISA: VMware ESXi and Workstation TOCTOU Race Condition Vulnerability

CVSS 3.1
8.2 high
EPSS
2%p74
Published
()
KEV added
AI analysis

VMware ESXi and Workstation contain a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) that can lead to an out-of-bounds write in the virtual machine's VMX process. To trigger it, a malicious actor needs local administrative privileges inside a guest virtual machine, where the race condition between the host's check and use of a resource can be exploited. Successful exploitation executes code as the VMX process on the host - effectively a guest-to-host escape, since the VMX process runs with host-level privileges on ESXi - reflected in the CVSS 3.1 score of 8.2 with changed scope. Affected products per the available data are VMware ESXi and Workstation, plus VMware Cloud Foundation and VMware Telco Cloud Infrastructure/Platform, which bundle the affected components; specific affected or fixed version ranges are not stated in the provided data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-04, confirming active in-the-wild exploitation (ransomware use is listed as unknown), though no public proof-of-concept code is known.

What to do: Upgrade ESXi, Workstation, VMware Cloud Foundation, and Telco Cloud deployments to the patched releases identified in Broadcom's security advisory (fixed version numbers are not present in the provided data, so confirm them directly in the advisory); because the flaw is on CISA KEV, BOD 22-01-bound organizations must apply vendor mitigations or patches by the KEV deadline or discontinue use of the product. As an interim measure, restrict local administrative privileges inside guest VMs to trusted users only, since guest admin access is the prerequisite for exploitation. Prioritize hosts that are internet-reachable or multi-tenant, where untrusted users are more likely to hold guest admin rights.

Affected
VMware ESXi
VMware Workstation
VMware Cloud Foundation
VMware Telco Cloud Infrastructure
VMware Telco Cloud Platform
Estimated exposure
masson the order of 100,000+ internet-exposed ESXi hosts, with the total ESXi/Workstation install base plausibly in the hundreds of thousands to millions — Public internet scans have repeatedly shown on the order of 100,000 ESXi hosts with exposed management interfaces, and ESXi is one of the most widely deployed enterprise hypervisors with a large Workstation desktop installed base, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

CISA Known Exploited Vulnerability
Affected
VMware ESXi and Workstation
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
esxi, cloud foundation, telco cloud infrastructure, telco cloud platform, workstation
Weakness
CWE-367
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news