CVE-2025-22226
KEVmassOut-of-Bounds Read in VMware ESXi, Workstation, and Fusion Leaks Host Memory via HGFS
CISA: VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability
CVE-2025-22226 is an information disclosure vulnerability in the HGFS (Host Guest File System) component of VMware ESXi, Workstation, and Fusion, caused by an out-of-bounds read (CWE-125) in the vmx process. It is triggered when a malicious actor who already holds administrative privileges inside a guest virtual machine interacts with HGFS, causing the vulnerable code to read beyond a buffer boundary. Successful exploitation allows the attacker to leak memory from the host-side vmx process, potentially exposing sensitive host or cross-VM data (confidentiality-only impact; CVSS 6.0 with scope change). Any organization running ESXi standalone or as part of VMware Cloud Foundation or the Telco Cloud products, as well as users of Workstation or Fusion desktop hypervisors, is potentially affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-03-04, confirming exploitation in the wild; no public PoC is known and ransomware use is listed as unknown (EPSS ~1.7%, 76th percentile).
What to do: Apply the patched releases published in Broadcom's VMware advisory (released alongside CISA's KEV entry on 2025-03-04) for ESXi, Workstation, Fusion, and any Cloud Foundation/Telco Cloud deployments; federal agencies must remediate per BOD 22-01 timelines. Where shared folders/HGFS are not required, disable them, and restrict administrative privileges inside guest VMs since guest admin access is the prerequisite for exploitation. Verify current build numbers against the advisory, as the source data does not specify fixed versions.
| VMware (Broadcom) ESXi | — |
| VMware (Broadcom) VMware Cloud Foundation (bundles ESXi) | — |
| VMware (Broadcom) VMware Telco Cloud Infrastructure | — |
| VMware (Broadcom) VMware Telco Cloud Platform | — |
| VMware (Broadcom) Workstation | — |
| VMware (Broadcom) Fusion | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
- Affected
- VMware ESXi, Workstation, and Fusion
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- vmware
- Products
- esxi, cloud foundation, fusion, telco cloud infrastructure, telco cloud platform, workstation
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N