CVE-2025-22224
CVE Published | 2025-03-04 |
---|---|
Related CWE(s) | CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition |
Related Vendor(s) | vmware |
Related Product(s) | cloud_foundation, esxi, workstation, telco_cloud_platform, telco_cloud_infrastructure |
Exploitation Reported (CISA KEV) | 2025-03-04 |
CVSS 3 Base Score | 8.2 (HIGH) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | LOCAL |
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph