Broadcom today pushed out patches for three VMware hypervisor-hijacking bugs, including one rated critical, that have already been found and exploited by criminals. The vulnerabilities, tracked as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, affect VMware ESXi, vSphere, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform. Updating to a fixed version will plug the holes. Microsoft spotted and reported to Broadcom all three bugs, which can be chained together to escape a guest virtual machine and gain full control of the hypervisor and host system, which would be bad. To escape the guest, one needs to be an administrator within the VM. "This is a situation where an attacker who has already compromised a virtual machine's guest OS and gained privileged access (administrator or root) could move into the hypervisor itself," according to a Q&A about the CVEs. The first and most critical flaw, CVE-2025-22224, is VCMI heap-overflow vulnerability that leads to an out-of-bounds write. It received a 9.3-out-of-10 CVSS rating. An attacker with local administrative privileges on a VM can abuse this hole to execute code as the Virtual Machine Executable (VMX) process running on the host. The second, CVE-2025-22225, is an 8.2-rated arbitrary write vulnerability. A miscreant with privileges within the VMX process can use this to trigger an arbitrary kernel write, which then leads to VM escape. And the third bug, CVE-2025-22226, is a 7.1-rated information-disclosure vulnera...
Unknown attackers exploit VMware hypervisor-hijack holes
The Register
·Jessica Lyons
·Published Mar 4, 2025
·Updated
Affected Software
12 affected components
VMware ESXi
VMware vSphere
VMware Workstation
VMware Fusion
VMware Cloud Foundation
VMware Telco Cloud Platform
VMware ESXi
VMware vSphere
VMware Workstation
VMware Fusion
VMware Cloud Foundation
VMware Telco Cloud Platform
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the discovery and patching of three critical vulnerabilities in VMware hypervisor software that are being actively exploited by attackers.
2
What vulnerabilities are highlighted in this news article?
The vulnerabilities are tracked as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, with one rated as critical.
3
Which VMware products are affected by these vulnerabilities?
Affected products include VMware ESXi, vSphere, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform.
4
What actions have been taken in response to these vulnerabilities?
Broadcom has released patches to address the vulnerabilities identified in the VMware hypervisor software.
5
What are the security implications of these hypervisor-hijacking vulnerabilities?
The vulnerabilities can potentially allow attackers to gain unauthorized access and control over virtual machines hosted on VMware environments.