Skip to content
COOEY

EXPOSURES › CVE-2025-22226

CVE-2025-22226

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-03-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-22226 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

VMware virtualization products have an information disclosure vulnerability actively exploited in the wild, potentially allowing memory leakage from privileged virtual machines.

VMware ESXi, Workstation, and Fusion products contain an information disclosure vulnerability due to an out-of-bounds read, allowing attackers with administrative privileges to leak memory. DIB organizations using these products must immediately patch to prevent potential data exposure and compliance violations (NIST 800-171 controls 3.1.1, 3.1.2). Verify patching effectiveness and review virtual machine access controls.

Shame score — A widely-used virtualization platform having an actively exploited information disclosure vulnerability demonstrates a significant security oversight with potential for data compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized