ZeroHour

CVE-2025-22226

KEVmass

Out-of-Bounds Read in VMware ESXi, Workstation, and Fusion Leaks Host Memory via HGFS

CISA: VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

CVSS 3.1
6.0 medium
EPSS
2%p76
Published
()
KEV added
AI analysis

CVE-2025-22226 is an information disclosure vulnerability in the HGFS (Host Guest File System) component of VMware ESXi, Workstation, and Fusion, caused by an out-of-bounds read (CWE-125) in the vmx process. It is triggered when a malicious actor who already holds administrative privileges inside a guest virtual machine interacts with HGFS, causing the vulnerable code to read beyond a buffer boundary. Successful exploitation allows the attacker to leak memory from the host-side vmx process, potentially exposing sensitive host or cross-VM data (confidentiality-only impact; CVSS 6.0 with scope change). Any organization running ESXi standalone or as part of VMware Cloud Foundation or the Telco Cloud products, as well as users of Workstation or Fusion desktop hypervisors, is potentially affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-03-04, confirming exploitation in the wild; no public PoC is known and ransomware use is listed as unknown (EPSS ~1.7%, 76th percentile).

What to do: Apply the patched releases published in Broadcom's VMware advisory (released alongside CISA's KEV entry on 2025-03-04) for ESXi, Workstation, Fusion, and any Cloud Foundation/Telco Cloud deployments; federal agencies must remediate per BOD 22-01 timelines. Where shared folders/HGFS are not required, disable them, and restrict administrative privileges inside guest VMs since guest admin access is the prerequisite for exploitation. Verify current build numbers against the advisory, as the source data does not specify fixed versions.

Affected
VMware (Broadcom) ESXi
VMware (Broadcom) VMware Cloud Foundation (bundles ESXi)
VMware (Broadcom) VMware Telco Cloud Infrastructure
VMware (Broadcom) VMware Telco Cloud Platform
VMware (Broadcom) Workstation
VMware (Broadcom) Fusion
Estimated exposure
mass≈100,000+ internet-exposed ESXi/vSphere hosts, plus a very large Workstation and Fusion desktop install base (order of magnitude: mass) — Public internet scans have repeatedly shown on the order of 100k+ ESXi/vSphere endpoints exposed to the internet and ESXi is among the most widely deployed enterprise hypervisors, with Workstation/Fusion adding millions of desktop…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

CISA Known Exploited Vulnerability
Affected
VMware ESXi, Workstation, and Fusion
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
esxi, cloud foundation, fusion, telco cloud infrastructure, telco cloud platform, workstation
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

In the news