CVE-2025-22224: VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.
Other sources
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of VMware ESXi and Workstation if mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-22224?
CVE-2025-22224 is rated as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-22224?
To mitigate CVE-2025-22224, update VMware ESXi and Workstation to the latest versions provided by VMware.
Who is affected by CVE-2025-22224?
CVE-2025-22224 affects users with local administrative privileges on VMware ESXi and Workstation.
What type of vulnerability is CVE-2025-22224?
CVE-2025-22224 is a TOCTOU (Time-of-Check Time-of-Use) vulnerability leading to out-of-bounds write.
What could an attacker do by exploiting CVE-2025-22224?
An attacker exploiting CVE-2025-22224 could execute arbitrary code as the virtual machine's VMX process on the host.