CVE-2025-22226

HIGH KEV RANSOMWARE

VMware ESXi, Workstation, and Fusion - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-22226 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 4, 2025, with confirmed use in ransomware campaigns.

Description

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

Scores

CVSS v3 7.1
EPSS 0.0423
EPSS Percentile 89.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2025-03-04
VulnCheck KEV 2025-03-04
ENISA EUVD EUVD-2025-7605
Ransomware Use Confirmed
CWE
CWE-125
Status published
Products (9)
vmware/cloud_foundation
vmware/esxi 7.0 (29 CPE variants)
vmware/esxi 8.0 (14 CPE variants)
vmware/fusion 13.0.0 - 13.6.3
vmware/telco_cloud_infrastructure 2.2
vmware/telco_cloud_infrastructure 2.5
vmware/telco_cloud_infrastructure 2.7
vmware/telco_cloud_infrastructure 3.0
vmware/telco_cloud_platform 2.0
Published Mar 04, 2025
KEV Added Mar 04, 2025
Tracked Since Feb 18, 2026