CVE-2025-22225
Description
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
In plain language
AI Act nowCVE-2025-22225 is a VMware ESXi flaw where an attacker who already has high privileges inside the VMX process can overwrite the host’s protected memory and break out to take control of the main server; this is a RED risk for environments that run ESXi components with such insider-level access.
CVE-2025-22225 is an arbitrary write vulnerability in VMware ESXi where an attacker with privileges within the VMX process can trigger an arbitrary kernel write to escape the sandbox and gain control of the ESXi host; it is listed in the CISA KEV set and is reported as used in ransomware campaigns.
What to do now
- Check whether you run VMware ESXi and whether you have any components/tenants that can reach or operate with VMX-process privileges.
- Inventory your ESXi versions and compare them to the fixed releases: ESXi80U3d-24585383, ESXi80U2d-24585300, or ESXi70U3s-24585291.
- Upgrade/patch VMware ESXi to the fixed version for your release branch (using the vendor Security Advisory linked in it_message).
- If you cannot patch immediately, apply the vendor-mitigation guidance from the Security Advisory and follow applicable cloud hardening guidance (per CISA’s KEV-required actions).
- Confirm patch deployment and monitor for ESXi/VMX-related suspicious activity around the time of any attacker presence.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-22225 and every CVE in our database. Create a free account — no credit card required.
Create Free Account