Broadcom warned customers today about three VMware zero-days, tagged as exploited in attacks and reported by the Microsoft Threat Intelligence Center. The vulnerabilities (CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226) impact VMware ESX products, including VMware ESXi, vSphere, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform. Attackers with privileged administrator or root access can chain these flaws to escape the virtual machine's sandbox. "This is a situation where an attacker who has already compromised a virtual machine's guest OS and gained privileged access (administrator or root) could move into the hypervisor itself," the company explained today. "Broadcom has information to suggest that exploitation of these issues has occurred 'in the wild'." Broadcom says CVE-2025-22224 is a critical-severity VCMI heap overflow vulnerability that enables local attackers with administrative privileges on the targeted VM to execute code as the VMX process running on the host. CVE-2025-22225 is an ESXi arbitrary write vulnerability that allows the VMX process to trigger arbitrary kernel writes, leading to a sandbox escape, while CVE-2025-22226 is described as an HGFS information-disclosure flaw that lets threat actors with admin permissions to leak memory from the VMX process. When asked if Microsoft had more information regarding the flaws' in-the-wild exploitation, a spokesperson told BleepingComputer the company "does not have anything additional to share at ...
Broadcom fixes three VMware zero-days exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Mar 4, 2025
·Updated
Affected Software
12 affected components
VMware ESXi
VMware vSphere
VMware Workstation
VMware Fusion
VMware Cloud Foundation
VMware Telco Cloud Platform
VMware ESXi
VMware vSphere
VMware Workstation
VMware Fusion
VMware Cloud Foundation
VMware Telco Cloud Platform
Frequently Asked Questions
1
What are the zero-day vulnerabilities mentioned in the article?
The vulnerabilities are identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226.
2
Which products are affected by these VMware vulnerabilities?
The affected products include VMware ESXi, VMware vSphere, VMware Workstation, VMware Fusion, VMware Cloud Foundation, and VMware Telco Cloud Platform.
3
Who reported the exploitation of these vulnerabilities?
The Microsoft Threat Intelligence Center reported the exploitation of these vulnerabilities.
4
What is the main risk associated with these zero-day vulnerabilities?
The main risk is that they are actively being exploited in attacks, which poses significant security threats to affected systems.
5
How does Broadcom recommend customers address these vulnerabilities?
Broadcom recommends customers apply the necessary patches to mitigate the security risks associated with these vulnerabilities.