CVE-2025-22225

Published Mar 4, 2025

Last updated 17 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-22225 is an arbitrary file write vulnerability that affects VMware ESXi. An attacker with privileges inside the VMX process can exploit this vulnerability to trigger arbitrary kernel writes, which can lead to a sandbox escape. The vulnerability has a CVSS base score of 8.2. This vulnerability is one of three zero-day flaws (CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226) that are being actively exploited. VMware has released patches for these vulnerabilities and urges customers to update their systems immediately. There are no known workarounds available.

Description
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
Source
security@vmware.com
NVD status
Analyzed
Products
esxi, cloud_foundation, telco_cloud_infrastructure, telco_cloud_platform

Risk scores

CVSS 3.1

Type
Primary
Base score
8.2
Impact score
6
Exploitability score
1.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
VMware ESXi Arbitrary Write Vulnerability
Exploit added on
Mar 4, 2025
Exploit action due
Mar 25, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-787
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-123

Social media

Hype score
Not currently trending
  1. Heads-up: CVE-2025-22225 is under active exploitation. VMware ESXi contains an arbitrary write vulnerability. Risk 51/100 · EPSS 1% · CVSS 8.2. This belongs at the top of your patch queue. https://t.co/ZZXxKeCUjO #ThreatIntel #VMware #ActivelyExploited

    @BytesNora

    9 Aug 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🔍 Why is VMware CVE-2025-22225 so dangerous? If a hacker compromises a single virtual machine, they can exploit this USB controller bug to escape the sandbox and encrypt the entire ESXi host and all running VMs! 😱 See the fix 👇 https://t.co/76LKfi063L #AppSec #TechNews

    @udaypatil077

    8 Jul 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ⚠️ VMware Admins: Running ESXi, Workstation, or Fusion? CVE-2025-22225 is a critical sandbox escape flaw in the USB controller interface. A local VM user can execute arbitrary code on the hypervisor host! Patch & mitigation guide 👇 https://t.co/DnrfEKJTXT #DevSecOps

    @secureblognews

    8 Jul 2026

    49 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CRITICAL ALERT: VMware ESXi Sandbox Escape flaw (CVE-2025-22225) lets attackers break out of VMs and take over the host server! 🛑 Threat actors are targeting unpatched hypervisors to deploy enterprise ransomware. Full fix 👇 https://t.co/Qffg6Qze10 #CyberSecurity #ESX

    @CyberUpdates365

    8 Jul 2026

    68 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. #ICYMI CVE-2025-22225 in VMware ESXi now used in active ransomware attacks. https://t.co/X161K7vYcn

    @jc_vazquez

    20 Mar 2026

    117 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-22225 | 53 mentions | Vendors: vmware | Active Exploitation | cloud_foundation, esxi, telco_cloud_infrastructure | 2[.]0, 2[.]2, 2[.]5, 2[.]7, 3[.]0, 4[.]0 VulnSocial - your risk exposure provider. https://t.co/ns4js3puEK

    @vulnsocial

    6 Mar 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Ransomware actors are actively exploiting VMware ESXi (CVE-2025-22225). Do you know which of your hypervisors are internet-exposed right now? Audit access, remove direct exposure, and patch immediately. #CyberSecurity #Ransomware https://t.co/Us3k0DCoAA

    @ReremData

    19 Feb 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. 🚨 ¡ALERTA CRÍTICA EN VMWARE! 🚨 Se explota el CVE-2025-22225 en ESXi. Es un VM Escape: un atacante puede saltar de una VM y tomar control total del host. CISA ya confirmó ataques reales. 🛡️ ✅Parchea ya (Broadcom)✅Aísla consolas de gestión✅Revisa logs #CyberSe

    @Priority_IT

    13 Feb 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks Source: @The_Cyber_News https://t.co/9TBGwvGyZc CISA recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability.

    @upgradeoptions

    10 Feb 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CISA: VMware ESXi flaw (CVE-2025-22225) now exploited in ransomware attacks via @BleepinComputer #Proficio #ThreatNews #Cybersecurity #MSSP #MDR https://t.co/xRkTwO1Drq

    @proficioinc

    9 Feb 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. #CISA confirms that #ransomware gangs are exploiting the #VMware ESXi sandbox escape flaw CVE-2025-22225. #CyberSecurity #InfoSec https://t.co/MSjG1LO8lz https://t.co/goZDXxm0g3

    @twelvesec

    8 Feb 2026

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2025-22225 sandbox escape confirmed as ransomware attack vector. Exploitation toolkit predates Broadcom's patch by a full year. Read more: https://t.co/vDn2GXPOFv

    @probablypwned

    8 Feb 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. CISA: Ransomware intrusions exploiting VMware ESXi bug ongoing https://t.co/9S5Um8onEy BleepingComputer reports that the high-severity VMware ESXi sandbox escape issue, tracked as CVE-2025-22225, was confirmed by the Cybersecurity and Infrastructure Security Agency to have bee

    @f1tym1

    6 Feb 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CISA confirms active exploitation of VMware ESXi vulnerability CVE-2025-22225 in ransomware attacks. Organizations urged to patch immediately. https://t.co/0E61dELnSp #Security #VMware #Ransomware #CISA #Vulnerability #Patch #Cyber #Threat #Attack #Malware #Exploit #Defense https

    @dailytechonx

    6 Feb 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. “VMware ESXi” platformasında "0-day" təhlükəsizlik boşluğu (CVE-2025-22225) aşkarlanıb. #ETX #MilliCERT #cybersecurity #kibertəhlükəsizlik #xəbərdarlıq https://t.co/RfyndNVDhi

    @CERTAzerbaijan

    6 Feb 2026

    78 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks Source: @The_Cyber_News https://t.co/9TBGwvH6OK CISA recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability. h

    @upgradeoptions

    6 Feb 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🚨 CISA Confirms Ransomware Actors Are Exploiting VMware ESXi Sandbox-Escape CVE-2025-22225 CISA confirmed CVE-2025-22225 (VMware ESXi sandbox escape) is being used in ransomware attacks nearly a year after it entered the KEV catalog, with details withheld—reinforcing that

    @ThreatSynop

    6 Feb 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. CISA: Ransomware intrusions exploiting VMware ESXi bug ongoing https://t.co/9S5Um8onEy BleepingComputer reports that the high-severity VMware ESXi sandbox escape issue, tracked as CVE-2025-22225, was confirmed by the Cybersecurity and Infrastructure Security Agency to have bee

    @f1tym1

    6 Feb 2026

    83 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. New developments from Help Net Security indicate that CISA has confirmed the exploitation of a critical VMware ESXi vulnerability, CVE-2025-22225, in active ransomware campaigns. This follows earlier Broadcom disclosures in March 2025 about a trio of zero-day flaws in VMware

    @ox0ffff

    6 Feb 2026

    94 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CISA confirms exploitation of VMware ESXi flaw by ransomware attackers https://t.co/gjsVLyiSyg CVE-2025-22225, a VMware ESXi arbitrary write vulnerability, is being used in ransomware campaigns, CISA confirmed on Wednesday by updating the vulnerability’s entry in its Known Exp

    @f1tym1

    5 Feb 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🚨 CISA Flags VMware ESXi CVE-2025-22225 as Ransomware-Exploited After Huntress Links It to Zero-Day Exploit Toolkit CISA updated KEV to confirm ransomware actors are exploiting VMware ESXi arbitrary-write flaw CVE-2025-22225 (patched March 2025), with researchers tying

    @ThreatSynop

    5 Feb 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. CISA confirms exploitation of VMware ESXi flaw by ransomware attackers: CVE-2025-22225, a VMware ESXi arbitrary write vulnerability, is being used in ransomware campaigns, CISA confirmed on Wednesday by updating the vulnerability’s entry in its Known… https://t.co/eLyWSonEaU

    @shah_sheikh

    5 Feb 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🚨 Urgent cybersecurity alert: CISA confirms ransomware gangs are now actively exploiting a VMware ESXi 0-day sandbox escape vulnerability (CVE-2025-22225) that lets attackers break out of VMs and control hypervisors — with ransomware deployment now observed in the wild. Patc

    @vuln_tracker

    5 Feb 2026

    126 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 Urgent cybersecurity alert: CISA confirms ransomware gangs are now actively exploiting a VMware ESXi 0-day sandbox escape vulnerability (CVE-2025-22225) that lets attackers break out of VMs and control hypervisors — with ransomware deployment now observed in the wild. Patc

    @vuln_tracker

    5 Feb 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 【リンク集:2月4日〜5日のセキュリティ関連ニュース/記事】 <脆弱性> ・米CISA、VMware ESXiの脆弱性がランサムウェア攻撃に悪用されていると警告(CVE-2025-22225) https://t.co/TX3AYadGWx ・React2Shellを悪用した攻撃

    @MachinaRecord

    5 Feb 2026

    126 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 以前ゼロデイ攻撃に使用されていたVMware ESXiの重大な脆弱性CVE-2025-22225がランサムウェア攻撃にも悪用され始めたことが報告されています。

    @MalwareBibleJP

    5 Feb 2026

    1949 Impressions

    8 Retweets

    30 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  27. CISA reports active exploitation of VMware ESXi flaw CVE-2025-22225 in ransomware attacks. Broadcom patched this and related zero-days in March 2025. Added to CISA’s Known Exploited Vulnerabilities list. #VMware #Ransomware #USA https://t.co/owab7R8GGV

    @TweetThreatNews

    5 Feb 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 🚨 CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks Source: https://t.co/MEi11toP1l CISA recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability. This flaw, patch

    @The_Cyber_News

    5 Feb 2026

    22325 Impressions

    153 Retweets

    419 Likes

    119 Bookmarks

    8 Replies

    3 Quotes

  29. 🚨 CISA: VMware ESXi “0-day” (CVE-2025-22225) now exploited by ransomware crews for hypervisor takeover CISA says ransomware actors are actively exploiting CVE-2025-22225 (ESXi VMX sandbox escape via arbitrary kernel write), typically chained with CVE-2025-22224/22226 to br

    @ThreatSynop

    5 Feb 2026

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 米国CISA(サイバーセキュリティ・社会基盤安全保障庁)が、VMware ESXiに存在する脆弱性「CVE-2025-22225」がランサムウェア攻撃グループによって活発に悪用されているとして、注意を呼びかけています。

    @omomuki_tech

    5 Feb 2026

    214 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. New developments from Security Affairs indicate that ransomware groups are actively exploiting CVE-2025-22225, a critical sandbox escape flaw in VMware ESXi, to conduct targeted attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed exploitation

    @ox0ffff

    5 Feb 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. VMware ESXiの脆弱性CVE-2025-22225がランサムウェアに悪用された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログが更新。 https://t.co/0m9mGnj45G

    @__kokumoto

    4 Feb 2026

    3592 Impressions

    19 Retweets

    42 Likes

    9 Bookmarks

    0 Replies

    0 Quotes

  33. 🚨 VMware ESXi sandbox-escape (CVE-2025-22225) now tied to active ransomware exploitation, CISA confirms CISA updated KEV to confirm ransomware actors are exploiting CVE-2025-22225 (ESXi VMX sandbox escape via arbitrary kernel write), elevating it from “patched” to “weapo

    @ThreatSynop

    4 Feb 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. CVE-2025-22225 in VMware ESXi now used in active ransomware attacks: Ransomware groups now exploit VMware ESXi vulnerability CVE-2025-22225, patched by Broadcom in March 2025. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirms that… https://t.co/E0Wpkz9Y4

    @shah_sheikh

    4 Feb 2026

    56 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. CVE-2025-22225 in VMware ESXi now used in active ransomware attacks https://t.co/VFpM2Gm0D0 #BreakingNews https://t.co/QzkwJghHxv

    @evanderburg

    4 Feb 2026

    87 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 📢 𝐂𝐈𝐒𝐀: 𝐕𝐌𝐰𝐚𝐫𝐞 𝐄𝐒𝐗𝐢 𝐟𝐥𝐚𝐰 𝐧𝐨𝐰 𝐞𝐱𝐩𝐥𝐨𝐢𝐭𝐞𝐝 𝐢𝐧 𝐫𝐚𝐧𝐬𝐨𝐦𝐰𝐚𝐫𝐞 𝐚𝐭𝐭𝐚𝐜𝐤𝐬 • CISA confirmed ransomware groups are exploiting a high-severity

    @PurpleOps_io

    4 Feb 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. CVE-2025-22225 in VMware ESXi now used in active ransomware Attacks https://t.co/hbzy9MijnH #securityaffairs #hacking

    @securityaffairs

    4 Feb 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. CVE-2025-22225 https://t.co/OEPZVxatzz

    @UK_Daniel_Card

    4 Feb 2026

    1766 Impressions

    0 Retweets

    14 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  39. 🚨 Breaking: Chinese-linked hackers are exploiting VMware ESXi zero-days to break out of virtual machines and seize control of hypervisors! 😱 In a recent attack spotted by Huntress in December 2025, threat actors used three critical flaws (CVE-2025-22224, CVE-2025-22225,

    @justabreach

    9 Jan 2026

    120 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  40. The Great VM Escape: ESXi Exploitation in the Wild VMware:CVE-2025-22226+CVE-2025-22224+CVE-2025-22225 https://t.co/jenLx2KClQ Key: When vmci.sys is loaded, it owns the VMCI adapter and actively uses these same I/O ports. Two drivers cannot safely share the same hardware, if ht

    @blackorbird

    9 Jan 2026

    12917 Impressions

    28 Retweets

    138 Likes

    72 Bookmarks

    1 Reply

    2 Quotes

  41. 中国系脅威主体はVMware ESXiのゼロデイ脆弱性を開示の1年前には悪用していたとみられる。Huntress社報告。CVE-2025-22224, CVE-2025-22225, CVE-2025-22226の3件。攻撃用バイナリのPDBパスに2024_02_19の文字列。攻撃用バイナリ

    @__kokumoto

    8 Jan 2026

    1177 Impressions

    3 Retweets

    10 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  42. CVE-2025-22224 + CVE-2025-22225 + CVE-2025-22226 = ebat fbi

    @networker_sup

    23 Jul 2025

    44 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. #Vulnerability #CVE202522224 CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Critical VMware Vulnerabilities Exploited https://t.co/mer0g3Dson

    @Komodosec

    11 Apr 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. >CVE-2025-22224、CVE-2025-22225、CVE-2025-22226 複数の脆弱性情報を活用し、侵害できる能力があるというか、当然攻撃を試すラボも拠点に持っているんでしょうね

    @ETomatot24044

    31 Mar 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. Critical VMware vulnerabilities patched (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) - one actively exploited. ESXi, Workstation, Fusion at risk. Requires local admin access but can lead to code execution & sandbox escape. Patch now! https://t.co/2Z3nv9MVl9

    @RedTeamNewsBlog

    24 Mar 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Recent #VMware vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) pose a critical threat, allowing attackers to escape compromised VMs and seize control of the hypervisor. The active exploitation of these flaws has made this risk more severe than ever, with… https:/

    @sygnia_labs

    19 Mar 2025

    93 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. 3 ثغرات خطيرة في VMware: مخاطر حقيقية وتحديثات عاجلة أصدرت Broadcom في 4 مارس تحديثات طارئة لمعالجة 3 ثغرات خطيرة (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) تؤثر على ESXi وWorkstation وFusion. إحدى هذه الثغرات (CVE-2025-22224) تم استغلالها فعليًا وتسمح للمهاجمين بالخروج…

    @KasperskyKSA

    18 Mar 2025

    200 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. Three VMware Vulnerabilities: Key Risks and Urgent Patches On March 4, Broadcom released emergency updates for three critical VMware vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) affecting ESXi, Workstation, and Fusion. At least one (CVE-2025-22224) has been…

    @KasperskyKSA

    17 Mar 2025

    172 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. VMware three vulnerabilities CVE-2025-22224, CVE-2025-22225, CVE-2025-22226. hackers are back in business.

    @XiaoChuStudio

    15 Mar 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  50. CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Zero-Day Vulnerabilities in VMware ESXi, Workstation and Fusion Exploited https://t.co/vW1vyg6OAh https://t.co/giNB4ixH3n

    @NickBla41002745

    14 Mar 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations