CVE-2025-22226

CVE Published 2025-03-04
Related CWE(s) CWE-125: Out-of-bounds Read
Related Vendor(s) vmware
Related Product(s) cloud_foundation, esxi, workstation, telco_cloud_platform, fusion, telco_cloud_infrastructure
Exploitation Reported (CISA KEV) 2025-03-04
CVSS 3 Base Score 6.0 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References