CVE-2025-22225

Published Mar 4, 2025

Last updated 3 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-22225 is an arbitrary file write vulnerability that affects VMware ESXi. An attacker with privileges inside the VMX process can exploit this vulnerability to trigger arbitrary kernel writes, which can lead to a sandbox escape. The vulnerability has a CVSS base score of 8.2. This vulnerability is one of three zero-day flaws (CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226) that are being actively exploited. VMware has released patches for these vulnerabilities and urges customers to update their systems immediately. There are no known workarounds available.

Description
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
Source
security@vmware.com
NVD status
Analyzed
Products
esxi, cloud_foundation, telco_cloud_infrastructure, telco_cloud_platform

Risk scores

CVSS 3.1

Type
Primary
Base score
8.2
Impact score
6
Exploitability score
1.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
VMware ESXi Arbitrary Write Vulnerability
Exploit added on
Mar 4, 2025
Exploit action due
Mar 25, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-787
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-123

Social media

Hype score
Not currently trending
  1. 🚨 CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks Source: @The_Cyber_News https://t.co/9TBGwvGyZc CISA recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability.

    @upgradeoptions

    10 Feb 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CISA: VMware ESXi flaw (CVE-2025-22225) now exploited in ransomware attacks via @BleepinComputer #Proficio #ThreatNews #Cybersecurity #MSSP #MDR https://t.co/xRkTwO1Drq

    @proficioinc

    9 Feb 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. #CISA confirms that #ransomware gangs are exploiting the #VMware ESXi sandbox escape flaw CVE-2025-22225. #CyberSecurity #InfoSec https://t.co/MSjG1LO8lz https://t.co/goZDXxm0g3

    @twelvesec

    8 Feb 2026

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-22225 sandbox escape confirmed as ransomware attack vector. Exploitation toolkit predates Broadcom's patch by a full year. Read more: https://t.co/vDn2GXPOFv

    @probablypwned

    8 Feb 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. CISA: Ransomware intrusions exploiting VMware ESXi bug ongoing https://t.co/9S5Um8onEy BleepingComputer reports that the high-severity VMware ESXi sandbox escape issue, tracked as CVE-2025-22225, was confirmed by the Cybersecurity and Infrastructure Security Agency to have bee

    @f1tym1

    6 Feb 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CISA confirms active exploitation of VMware ESXi vulnerability CVE-2025-22225 in ransomware attacks. Organizations urged to patch immediately. https://t.co/0E61dELnSp #Security #VMware #Ransomware #CISA #Vulnerability #Patch #Cyber #Threat #Attack #Malware #Exploit #Defense https

    @dailytechonx

    6 Feb 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. “VMware ESXi” platformasında "0-day" təhlükəsizlik boşluğu (CVE-2025-22225) aşkarlanıb. #ETX #MilliCERT #cybersecurity #kibertəhlükəsizlik #xəbərdarlıq https://t.co/RfyndNVDhi

    @CERTAzerbaijan

    6 Feb 2026

    78 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks Source: @The_Cyber_News https://t.co/9TBGwvH6OK CISA recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability. h

    @upgradeoptions

    6 Feb 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 CISA Confirms Ransomware Actors Are Exploiting VMware ESXi Sandbox-Escape CVE-2025-22225 CISA confirmed CVE-2025-22225 (VMware ESXi sandbox escape) is being used in ransomware attacks nearly a year after it entered the KEV catalog, with details withheld—reinforcing that

    @ThreatSynop

    6 Feb 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CISA: Ransomware intrusions exploiting VMware ESXi bug ongoing https://t.co/9S5Um8onEy BleepingComputer reports that the high-severity VMware ESXi sandbox escape issue, tracked as CVE-2025-22225, was confirmed by the Cybersecurity and Infrastructure Security Agency to have bee

    @f1tym1

    6 Feb 2026

    83 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. New developments from Help Net Security indicate that CISA has confirmed the exploitation of a critical VMware ESXi vulnerability, CVE-2025-22225, in active ransomware campaigns. This follows earlier Broadcom disclosures in March 2025 about a trio of zero-day flaws in VMware

    @ox0ffff

    6 Feb 2026

    94 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CISA confirms exploitation of VMware ESXi flaw by ransomware attackers https://t.co/gjsVLyiSyg CVE-2025-22225, a VMware ESXi arbitrary write vulnerability, is being used in ransomware campaigns, CISA confirmed on Wednesday by updating the vulnerability’s entry in its Known Exp

    @f1tym1

    5 Feb 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 CISA Flags VMware ESXi CVE-2025-22225 as Ransomware-Exploited After Huntress Links It to Zero-Day Exploit Toolkit CISA updated KEV to confirm ransomware actors are exploiting VMware ESXi arbitrary-write flaw CVE-2025-22225 (patched March 2025), with researchers tying

    @ThreatSynop

    5 Feb 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CISA confirms exploitation of VMware ESXi flaw by ransomware attackers: CVE-2025-22225, a VMware ESXi arbitrary write vulnerability, is being used in ransomware campaigns, CISA confirmed on Wednesday by updating the vulnerability’s entry in its Known… https://t.co/eLyWSonEaU

    @shah_sheikh

    5 Feb 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 Urgent cybersecurity alert: CISA confirms ransomware gangs are now actively exploiting a VMware ESXi 0-day sandbox escape vulnerability (CVE-2025-22225) that lets attackers break out of VMs and control hypervisors — with ransomware deployment now observed in the wild. Patc

    @vuln_tracker

    5 Feb 2026

    126 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 Urgent cybersecurity alert: CISA confirms ransomware gangs are now actively exploiting a VMware ESXi 0-day sandbox escape vulnerability (CVE-2025-22225) that lets attackers break out of VMs and control hypervisors — with ransomware deployment now observed in the wild. Patc

    @vuln_tracker

    5 Feb 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 【リンク集:2月4日〜5日のセキュリティ関連ニュース/記事】 <脆弱性> ・米CISA、VMware ESXiの脆弱性がランサムウェア攻撃に悪用されていると警告(CVE-2025-22225) https://t.co/TX3AYadGWx ・React2Shellを悪用した攻撃

    @MachinaRecord

    5 Feb 2026

    126 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 以前ゼロデイ攻撃に使用されていたVMware ESXiの重大な脆弱性CVE-2025-22225がランサムウェア攻撃にも悪用され始めたことが報告されています。

    @MalwareBibleJP

    5 Feb 2026

    1949 Impressions

    8 Retweets

    30 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  19. CISA reports active exploitation of VMware ESXi flaw CVE-2025-22225 in ransomware attacks. Broadcom patched this and related zero-days in March 2025. Added to CISA’s Known Exploited Vulnerabilities list. #VMware #Ransomware #USA https://t.co/owab7R8GGV

    @TweetThreatNews

    5 Feb 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨 CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks Source: https://t.co/MEi11toP1l CISA recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability. This flaw, patch

    @The_Cyber_News

    5 Feb 2026

    22325 Impressions

    153 Retweets

    419 Likes

    119 Bookmarks

    8 Replies

    3 Quotes

  21. 🚨 CISA: VMware ESXi “0-day” (CVE-2025-22225) now exploited by ransomware crews for hypervisor takeover CISA says ransomware actors are actively exploiting CVE-2025-22225 (ESXi VMX sandbox escape via arbitrary kernel write), typically chained with CVE-2025-22224/22226 to br

    @ThreatSynop

    5 Feb 2026

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 米国CISA(サイバーセキュリティ・社会基盤安全保障庁)が、VMware ESXiに存在する脆弱性「CVE-2025-22225」がランサムウェア攻撃グループによって活発に悪用されているとして、注意を呼びかけています。

    @omomuki_tech

    5 Feb 2026

    214 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. New developments from Security Affairs indicate that ransomware groups are actively exploiting CVE-2025-22225, a critical sandbox escape flaw in VMware ESXi, to conduct targeted attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed exploitation

    @ox0ffff

    5 Feb 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. VMware ESXiの脆弱性CVE-2025-22225がランサムウェアに悪用された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログが更新。 https://t.co/0m9mGnj45G

    @__kokumoto

    4 Feb 2026

    3592 Impressions

    19 Retweets

    42 Likes

    9 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 VMware ESXi sandbox-escape (CVE-2025-22225) now tied to active ransomware exploitation, CISA confirms CISA updated KEV to confirm ransomware actors are exploiting CVE-2025-22225 (ESXi VMX sandbox escape via arbitrary kernel write), elevating it from “patched” to “weapo

    @ThreatSynop

    4 Feb 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. CVE-2025-22225 in VMware ESXi now used in active ransomware attacks: Ransomware groups now exploit VMware ESXi vulnerability CVE-2025-22225, patched by Broadcom in March 2025. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirms that… https://t.co/E0Wpkz9Y4

    @shah_sheikh

    4 Feb 2026

    56 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. CVE-2025-22225 in VMware ESXi now used in active ransomware attacks https://t.co/VFpM2Gm0D0 #BreakingNews https://t.co/QzkwJghHxv

    @evanderburg

    4 Feb 2026

    87 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 📢 𝐂𝐈𝐒𝐀: 𝐕𝐌𝐰𝐚𝐫𝐞 𝐄𝐒𝐗𝐢 𝐟𝐥𝐚𝐰 𝐧𝐨𝐰 𝐞𝐱𝐩𝐥𝐨𝐢𝐭𝐞𝐝 𝐢𝐧 𝐫𝐚𝐧𝐬𝐨𝐦𝐰𝐚𝐫𝐞 𝐚𝐭𝐭𝐚𝐜𝐤𝐬 • CISA confirmed ransomware groups are exploiting a high-severity

    @PurpleOps_io

    4 Feb 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. CVE-2025-22225 in VMware ESXi now used in active ransomware Attacks https://t.co/hbzy9MijnH #securityaffairs #hacking

    @securityaffairs

    4 Feb 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. CVE-2025-22225 https://t.co/OEPZVxatzz

    @UK_Daniel_Card

    4 Feb 2026

    1766 Impressions

    0 Retweets

    14 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  31. 🚨 Breaking: Chinese-linked hackers are exploiting VMware ESXi zero-days to break out of virtual machines and seize control of hypervisors! 😱 In a recent attack spotted by Huntress in December 2025, threat actors used three critical flaws (CVE-2025-22224, CVE-2025-22225,

    @justabreach

    9 Jan 2026

    120 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  32. The Great VM Escape: ESXi Exploitation in the Wild VMware:CVE-2025-22226+CVE-2025-22224+CVE-2025-22225 https://t.co/jenLx2KClQ Key: When vmci.sys is loaded, it owns the VMCI adapter and actively uses these same I/O ports. Two drivers cannot safely share the same hardware, if ht

    @blackorbird

    9 Jan 2026

    12917 Impressions

    28 Retweets

    138 Likes

    72 Bookmarks

    1 Reply

    2 Quotes

  33. 中国系脅威主体はVMware ESXiのゼロデイ脆弱性を開示の1年前には悪用していたとみられる。Huntress社報告。CVE-2025-22224, CVE-2025-22225, CVE-2025-22226の3件。攻撃用バイナリのPDBパスに2024_02_19の文字列。攻撃用バイナリ

    @__kokumoto

    8 Jan 2026

    1177 Impressions

    3 Retweets

    10 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  34. CVE-2025-22224 + CVE-2025-22225 + CVE-2025-22226 = ebat fbi

    @networker_sup

    23 Jul 2025

    44 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. #Vulnerability #CVE202522224 CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Critical VMware Vulnerabilities Exploited https://t.co/mer0g3Dson

    @Komodosec

    11 Apr 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. >CVE-2025-22224、CVE-2025-22225、CVE-2025-22226 複数の脆弱性情報を活用し、侵害できる能力があるというか、当然攻撃を試すラボも拠点に持っているんでしょうね

    @ETomatot24044

    31 Mar 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. Critical VMware vulnerabilities patched (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) - one actively exploited. ESXi, Workstation, Fusion at risk. Requires local admin access but can lead to code execution & sandbox escape. Patch now! https://t.co/2Z3nv9MVl9

    @RedTeamNewsBlog

    24 Mar 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Recent #VMware vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) pose a critical threat, allowing attackers to escape compromised VMs and seize control of the hypervisor. The active exploitation of these flaws has made this risk more severe than ever, with… https:/

    @sygnia_labs

    19 Mar 2025

    93 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. 3 ثغرات خطيرة في VMware: مخاطر حقيقية وتحديثات عاجلة أصدرت Broadcom في 4 مارس تحديثات طارئة لمعالجة 3 ثغرات خطيرة (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) تؤثر على ESXi وWorkstation وFusion. إحدى هذه الثغرات (CVE-2025-22224) تم استغلالها فعليًا وتسمح للمهاجمين بالخروج…

    @KasperskyKSA

    18 Mar 2025

    200 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Three VMware Vulnerabilities: Key Risks and Urgent Patches On March 4, Broadcom released emergency updates for three critical VMware vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) affecting ESXi, Workstation, and Fusion. At least one (CVE-2025-22224) has been…

    @KasperskyKSA

    17 Mar 2025

    172 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. VMware three vulnerabilities CVE-2025-22224, CVE-2025-22225, CVE-2025-22226. hackers are back in business.

    @XiaoChuStudio

    15 Mar 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  42. CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Zero-Day Vulnerabilities in VMware ESXi, Workstation and Fusion Exploited https://t.co/vW1vyg6OAh https://t.co/giNB4ixH3n

    @NickBla41002745

    14 Mar 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. Tech alert: Critical VMware vulnerabilities are putting systems at risk! Discover how CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 could impact ESXi, Workstation, and more. Protect your data now! Read the advisory for more. https://t.co/5cS5XkWqLH #CyberSecurity https://t

    @sequretek_sqtk

    14 Mar 2025

    31 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  44. VMware Patches 3 Zero-Day Vulnerabilities After Active Exploitation ⚠️ https://t.co/9vjyWHCndI Broadcom has addressed three zero-day vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) in #VMware ESXi, Workstation, and Fusion, following reports of active… https://

    @Huntio

    13 Mar 2025

    84 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. On March 4th, Broadcom released patches for vulnerabilities affecting VMware products: CVE-2025-22224, CVE-2025-22225, CVE-2025-22226. Check out the details here: https://t.co/19v4hvhMGt

    @redhataugust

    12 Mar 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. 📣Critical Security Alert: VMware has issued a critical security alert for vulnerabilities in ESXi, Workstation, Fusion, Cloud Foundation, and Telco Cloud Infrastructure. These threats (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) are being exploited. Protect your systems now…

    @Helient

    11 Mar 2025

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Zero-Day Vulnerabilities in VMware ESXi, Workstation and Fusion Exploited https://t.co/KuDnAIxELh https://t.co/p0B8PSF0f0

    @NickBla41002745

    11 Mar 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Zero-Day Vulnerabilities in VMware ESXi, Workstation and Fusion Exploited https://t.co/4Y9SjCmopV https://t.co/gUIjoFz9hV

    @NickBla41002745

    10 Mar 2025

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Zero-Day Vulnerabilities in VMware ESXi, Workstation and Fusion Exploited https://t.co/7l0O8zkKm0 https://t.co/1oo0hqYi9x

    @dansantanna

    9 Mar 2025

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Zero-Day Vulnerabilities in VMware ESXi, Workstation and Fusion Exploited https://t.co/yHNLeIwmrS https://t.co/ZzTq5oioIf

    @secured_cyber

    7 Mar 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations