🟢 CVE-2025-22224

CVE-2025-22224 is a critical TOCTOU vulnerability in VMware virtualization products that allows VM escape from guest to host. Despite being in CISA KEV, this requires local administrative privileges within a VM and primarily affects infrastructure software not typically exposed to the internet.

← Back to Overview
LOW_RISK
Risk Level
9.3
CVSS Score
LOCAL
Attack Vector
Privilege Escalation
ATT&CK Tactic
T1068 — Exploitation for Privilege Escalation
ATT&CK Technique
LOW
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: OTHER

CVE Published: 2025-03-04

Added to CISA KEV: 2025-03-04 0 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2025-22224 is a critical security vulnerability affecting VMware ESXi, Workstation, and Fusion, which was disclosed by Broadcom on March 4, 2025, via VMSA-2025-0004 [1].

Vulnerability Overview
  • Type: Time-of-Check Time-of-Use (TOCTOU) race condition leading to an out-of-bounds write in the Virtual Machine Communication Interface (VMCI) [1] [4].
  • Severity: Critical, with a maximum CVSSv3 base score of 9.3 [1].
Exploitation and Impact
  • Attack Method: The vulnerability allows a malicious actor who already has local administrative privileges on a virtual machine to escape the VM and execute code as the virtual machine's VMX process running on the host [1] [4].
  • Requirements: It requires local administrative access within a guest VM; it is not a remote network exploit against the host itself.
  • Impact: Successful exploitation results in a full VM escape, providing the attacker with control over the host and the potential to compromise other virtual machines residing on that host [4].
Active Exploitation and Ransomware
  • In the Wild: The vulnerability has been reported as being actively exploited in the wild [5].
  • Ransomware Campaigns: There are reports indicating that these vulnerabilities (often grouped with CVE-2025-22225 and CVE-2025-22226) have been used by threat actors to actively deploy ransomware [3] [6].
Mitigation and Patch Status
  • Status: VMware released emergency updates on March 4, 2025, to address this issue [1].
  • Recommendation: Organizations should apply the patches provided in VMSA-2025-0004 immediately. If patching is not immediately possible, follow vendor-specific guidance or consider restricting VMCI usage if applicable [2].
*Note: While specific proof-of-concept code is often developed for such critical VM escape vulnerabilities, the primary defense remains applying the official vendor patches.*

Sources

  1. Support Content Notification - Support Portal - Broadcom support portal

    VMSA-2025-0004: VMware ESXi, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) ... VMCI heap-overflow vulnerability (CVE-2025-22224). Description: VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability t…

  2. CVE-2025-22224 Detail - NVD

    Description. VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor ... CVE-2025-22224 Detail Description VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an…

  3. CVE-2025-14917 | CyberSecurityBoard

    VMware Vulnerabilities Exploited Actively to Deploy Ransomware - On March 4, 2025, Broadcom released emergency updates to address three critical vulnerabilities – CVE-2025-22224 ... 41,500+ VMware ESXi Instances Vulnerable to Code Execution Attacks - We are scanning & reporting out VMware ESXi CVE-2…

  4. CVE‑2025‑22224 VMware TOCTOU VM Escape... | Fidelis Security

    Summary. CVE-2025-22224 is a critical TOCTOU (Time-of-Check Time-of-Use) vulnerability in VMware ESXi and Workstation. It lets an attacker with admin access inside a virtual machine run code on the host by exploiting a race condition. This allows full VM escape and could lead to control of the host…

  5. VMware vulnerabilities being actively epxloited. : r/msp - Reddit

    These vulnerabilities, collectively referred to as "ESXicape," have been actively exploited in the wild. CVE-2025-22224: A Time-of-Check Time-of ...

  6. CVE-2025-24865 | CyberSecurityBoard

    7 months ago Cybersecuritynews.com CVE-2024-53651 CVE-2025-25067 CVE-2025-24865 CVE-2025-22896 CVE-2025-23411 CVE-2023-37482 CVE-2024-54015 CVE-2022-38465 CVE-2025-24811 CVE-2025-20615 CVE ... VMware Vulnerabilities Exploited Actively to Deploy Ransomware - On March 4, 2025, Broadcom released emerge…