• News/
  • https://www.bleepingcomputer.com/news/security/broadcom-fixes-three-vmware-zero-days-exploited-in-attacks/

Broadcom fixes three VMware zero-days exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 4, 2025
·
Updated

Broadcom warned customers today about three VMware zero-days, tagged as exploited in attacks and reported by the Microsoft Threat Intelligence Center. The vulnerabilities (CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226) impact VMware ESX products, including VMware ESXi, vSphere, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform. Attackers with privileged administrator or root access can chain these flaws to escape the virtual machine's sandbox. "This is a situation where an attacker who has already compromised a virtual machine's guest OS and gained privileged access (administrator or root) could move into the hypervisor itself," the company explained today. "Broadcom has information to suggest that exploitation of these issues has occurred 'in the wild'." Broadcom says CVE-2025-22224 is a critical-severity VCMI heap overflow vulnerability that enables local attackers with administrative privileges on the targeted VM to execute code as the VMX process running on the host. CVE-2025-22225 is an ESXi arbitrary write vulnerability that allows the VMX process to trigger arbitrary kernel writes, leading to a sandbox escape, while CVE-2025-22226 is described as an HGFS information-disclosure flaw that lets threat actors with admin permissions to leak memory from the VMX process. When asked if Microsoft had more information regarding the flaws' in-the-wild exploitation, a spokesperson told BleepingComputer the company "does not have anything additional to share at ...

Read full article

Affected Software

12 affected components
VMware ESXi
VMware vSphere
VMware Workstation
VMware Fusion
VMware Cloud Foundation
VMware Telco Cloud Platform
VMware ESXi
VMware vSphere
VMware Workstation
VMware Fusion
VMware Cloud Foundation
VMware Telco Cloud Platform
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What are the zero-day vulnerabilities mentioned in the article?

The vulnerabilities are identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226.

2

Which products are affected by these VMware vulnerabilities?

The affected products include VMware ESXi, VMware vSphere, VMware Workstation, VMware Fusion, VMware Cloud Foundation, and VMware Telco Cloud Platform.

3

Who reported the exploitation of these vulnerabilities?

The Microsoft Threat Intelligence Center reported the exploitation of these vulnerabilities.

4

What is the main risk associated with these zero-day vulnerabilities?

The main risk is that they are actively being exploited in attacks, which poses significant security threats to affected systems.

5

How does Broadcom recommend customers address these vulnerabilities?

Broadcom recommends customers apply the necessary patches to mitigate the security risks associated with these vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203