CVE-2025-22224
Essential information
- Published
- 04/03/2025 12:15
- Modified
- 05/03/2025 16:18
- Author
- —
- Creator
- —
- CVSS
- 9.3 CRITICAL (v3.1)
- CISA KEV
- No
- CWE
- —
- CVSS vector
-
—
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H—
CVSS metrics
- Access vector
- —
- Access complexity
- —
- Authentication
- —
- Confidentiality impact
- —
- Integrity impact
- —
- Availability impact
- —
- Exploitability
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- LOCAL
- Attack complexity
- LOW
- Privileges required
- NONE
- User interaction
- NONE
- Scope
- CHANGED
- Confidentiality impact
- HIGH
- Integrity impact
- HIGH
- Availability impact
- HIGH
- Exploit code maturity
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- —
- Attack complexity
- —
- Attack requirements
- —
- Privileges required
- —
- User interaction
- —
- Confidentiality (V)
- —
- Confidentiality (S)
- —
- Integrity (V)
- —
- Integrity (S)
- —
- Availability (V)
- —
- Availability (S)
- —
- Exploit maturity
- —
Description
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
NVD status
- Status
- Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:-:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:beta:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_1:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_1a:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_1b:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_1c:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_1d:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_1e:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_2:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_2a:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_2c:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_2d:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_2e:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3c:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3d:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3e:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3f:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3g:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3i:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3j:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3k:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3l:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3m:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3n:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3o:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3p:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3q:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:7.0:update_3r:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:-:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:a:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:b:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:c:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:update_1:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:update_1a:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:update_1c:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:update_1d:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:update_2:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:update_2b:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:update_2c:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:update_3:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:update_3b:*:*:*:*:*:* |
| vmware / esxi | cpe:2.3:o:vmware:esxi:8.0:update_3c:*:*:*:*:*:* |
| vmware / cloud foundation | cpe:2.3:a:vmware:cloud_foundation:-:*:*:*:*:*:*:* |
| vmware / telco cloud infrastructure | cpe:2.3:a:vmware:telco_cloud_infrastructure:2.2:*:*:*:*:*:*:* |
| vmware / telco cloud infrastructure | cpe:2.3:a:vmware:telco_cloud_infrastructure:2.5:*:*:*:*:*:*:* |
| vmware / telco cloud infrastructure | cpe:2.3:a:vmware:telco_cloud_infrastructure:2.7:*:*:*:*:*:*:* |
| vmware / telco cloud infrastructure | cpe:2.3:a:vmware:telco_cloud_infrastructure:3.0:*:*:*:*:*:*:* |
| vmware / telco cloud platform | cpe:2.3:a:vmware:telco_cloud_platform:2.0:*:*:*:*:*:*:* |
| vmware / telco cloud platform | cpe:2.3:a:vmware:telco_cloud_platform:2.5:*:*:*:*:*:*:* |
| vmware / telco cloud platform | cpe:2.3:a:vmware:telco_cloud_platform:2.7:*:*:*:*:*:*:* |
| vmware / telco cloud platform | cpe:2.3:a:vmware:telco_cloud_platform:3.0:*:*:*:*:*:*:* |
| vmware / telco cloud platform | cpe:2.3:a:vmware:telco_cloud_platform:4.0:*:*:*:*:*:*:* |
| vmware / telco cloud platform | cpe:2.3:a:vmware:telco_cloud_platform:4.0.1:*:*:*:*:*:*:* |
| vmware / telco cloud platform | cpe:2.3:a:vmware:telco_cloud_platform:5.0:*:*:*:*:*:*:* |
| vmware / workstation | cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:* |