Multiple vulnerabilities have been discovered in VMware ESXi, Workstation, and Fusion could allow for local code execution. VMware ESXi, Workstation, and Fusion are all virtualization products that allow users to run virtual machines (VMs) on their computers. Successful exploitation of these vulnerability could allow for local code execution in the context of the administrator account. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
THREAT INTELLEGENCE:
VMware by Broadcom has information to suggest that exploitations of the vulnerabilities have occurred in the wild.
SYSTEMS AFFECTED:
-
VMware ESXi 8.0, 7.0
-
VMware Workstation 17.x
-
VMware Fusion 13.x
-
VMware Cloud Foundation 5.x, 4.5x
-
VMware Telco Cloud Platform 5.x, 4.x, 3.x, 2.x
-
VMware Telco Cloud Infrastructure 3.x, 2.x
RISK:
Government:
-
Large and medium government entities: High
-
Small government entities: Medium
Businesses:
-
Large and medium business entities: High
-
Small business entities: Medium
Home users: Low
TECHNICAL SUMMARY:
Multiple vulnerabilities have been discovered in VMware ESXi, Workstation, and Fusion which could allow for local code execution. Details of these vulnerabilities are as follows:
Tactic: Execution (TA0041):
Technique: Command and Scripting Interpreter (T1059):
-
VMware VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. (CVE-2025-22224)
-
VMware VMware ESXi contains an arbitrary write vulnerability. (CVE-2025-22225)
Details of lower-severity vulnerability are as follows:
-
VMware VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. (CVE-2025-22226)
Successful exploitation of these vulnerabilities could allow for local code execution in the context of the administrator account. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
RECOMMENDATIONS:
We recommend the following actions be taken:
-
Apply appropriate patches provided by WordPress to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
-
Safeguard 7.1: Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
-

