CVE-2025-22224

CVE Published 2025-03-04
Related CWE(s) CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
Related Vendor(s) vmware
Related Product(s) cloud_foundation, esxi, workstation, telco_cloud_platform, telco_cloud_infrastructure
Exploitation Reported (CISA KEV) 2025-03-04
CVSS 3 Base Score 8.2 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References