• News/
  • https://www.theregister.com/2025/03/04/vmware_plugs_three_hypervisorhijack_holes/

Unknown attackers exploit VMware hypervisor-hijack holes

The Register
·
Jessica Lyons
·
Published Mar 4, 2025
·
Updated

Broadcom today pushed out patches for three VMware hypervisor-hijacking bugs, including one rated critical, that have already been found and exploited by criminals. The vulnerabilities, tracked as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, affect VMware ESXi, vSphere, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform. Updating to a fixed version will plug the holes. Microsoft spotted and reported to Broadcom all three bugs, which can be chained together to escape a guest virtual machine and gain full control of the hypervisor and host system, which would be bad. To escape the guest, one needs to be an administrator within the VM. "This is a situation where an attacker who has already compromised a virtual machine's guest OS and gained privileged access (administrator or root) could move into the hypervisor itself," according to a Q&A about the CVEs. The first and most critical flaw, CVE-2025-22224, is VCMI heap-overflow vulnerability that leads to an out-of-bounds write. It received a 9.3-out-of-10 CVSS rating. An attacker with local administrative privileges on a VM can abuse this hole to execute code as the Virtual Machine Executable (VMX) process running on the host. The second, CVE-2025-22225, is an 8.2-rated arbitrary write vulnerability. A miscreant with privileges within the VMX process can use this to trigger an arbitrary kernel write, which then leads to VM escape. And the third bug, CVE-2025-22226, is a 7.1-rated information-disclosure vulnera...

Read full article

Affected Software

12 affected components
VMware ESXi
VMware vSphere
VMware Workstation
VMware Fusion
VMware Cloud Foundation
VMware Telco Cloud Platform
VMware ESXi
VMware vSphere
VMware Workstation
VMware Fusion
VMware Cloud Foundation
VMware Telco Cloud Platform
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the discovery and patching of three critical vulnerabilities in VMware hypervisor software that are being actively exploited by attackers.

2

What vulnerabilities are highlighted in this news article?

The vulnerabilities are tracked as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, with one rated as critical.

3

Which VMware products are affected by these vulnerabilities?

Affected products include VMware ESXi, vSphere, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform.

4

What actions have been taken in response to these vulnerabilities?

Broadcom has released patches to address the vulnerabilities identified in the VMware hypervisor software.

5

What are the security implications of these hypervisor-hijacking vulnerabilities?

The vulnerabilities can potentially allow attackers to gain unauthorized access and control over virtual machines hosted on VMware environments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203