Skip to content
COOEY

EXPOSURES › CVE-2025-22225

CVE-2025-22225

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-03-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-22225 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatchedrce

A critical arbitrary write vulnerability in VMware ESXi allows sandbox escapes and is actively exploited by ransomware.

VMware ESXi's arbitrary write flaw lets attackers with VMX process privileges trigger kernel writes, breaking the sandbox and enabling system escapes. This is a severe, avoidable failure because it is actively exploited in the wild and linked to ransomware, directly threatening DIB environments that rely on virtualization for secure workloads. Organizations must immediately patch ESXi and restrict VMX process access to prevent exploitation.

Shame score — A critical, actively exploited vulnerability in a foundational virtualization platform linked to ransomware demonstrates severe negligence and a massive exposure to DIB systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized