CVE Tools

Description

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

In plain language

AI Act now

CVE-2025-22225 is a VMware ESXi flaw where an attacker who already has high privileges inside the VMX process can overwrite the host’s protected memory and break out to take control of the main server; this is a RED risk for environments that run ESXi components with such insider-level access.

Executive summary

CVE-2025-22225 is an arbitrary write vulnerability in VMware ESXi where an attacker with privileges within the VMX process can trigger an arbitrary kernel write to escape the sandbox and gain control of the ESXi host; it is listed in the CISA KEV set and is reported as used in ransomware campaigns.

If affected, business impact
Full ESXi host takeoverRansomware reach to critical systemsPotential downtime and service outageData exposure from compromised host

What to do now

  1. Check whether you run VMware ESXi and whether you have any components/tenants that can reach or operate with VMX-process privileges.
  2. Inventory your ESXi versions and compare them to the fixed releases: ESXi80U3d-24585383, ESXi80U2d-24585300, or ESXi70U3s-24585291.
  3. Upgrade/patch VMware ESXi to the fixed version for your release branch (using the vendor Security Advisory linked in it_message).
  4. If you cannot patch immediately, apply the vendor-mitigation guidance from the Security Advisory and follow applicable cloud hardening guidance (per CISA’s KEV-required actions).
  5. Confirm patch deployment and monitor for ESXi/VMX-related suspicious activity around the time of any attacker presence.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:LAC:LPR:HUI:NS:CC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:HPrivileges Required
High
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 4 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Mar 4, 2025
Remediation due:Mar 25, 2025
Ransomware:Known ransomware use

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Initial Access
Privilege Escalation
View detailed technique mapping

References

and 18 more references View all →
2

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2025-22225 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store