💻 VMware security flaws are being exploited in the wild - Broadcom releases urgent fixes

chushpan

Professional
Messages
1,088
Reaction score
1,306
Points
113
👉 Broadcom has released security updates to address three actively exploited flaws in VMware ESXi, Workstation, and Fusion products that could lead to code execution and information disclosure.

📰 The list of vulnerabilities is as follows.

▫️ CVE-2025-22224 (CVSS score: 9.3) - A Time-of-Check Time-of-Use (TOCTOU) out-of-bounds write vulnerability that an attacker with local administrator privileges on a VM could use to execute code as a VMX process of a VM running on the host.
▫️ CVE-2025-22225 (CVSS score: 8.2) - An arbitrary write vulnerability that an attacker with privileges in the VMX process can use to escape the sandbox.
▫️ CVE-2025-22226 (CVSS score: 7.1) - An information disclosure vulnerability due to an out-of-bounds read in HGFS that an attacker with administrative privileges in the virtual machine can use to leak memory from the vmx process.
 
Top