Heap-based buffer overflow in VMware ESXi - CVE-2025-22224
Published: March 4, 2025
Vulnerability details
The vulnerability allows a malicious guest to execute arbitrary code on the hypervisor.
The vulnerability exists due to a boundary error in VMCI. A malicious guest with administrative privileges can trigger a heap-based buffer overflow and execute arbitrary code on the hypervisor in the context of VMX process.
Note, the vulnerability is being actively exploited in the wild.
Affected software
IBM Cloud Pak System
VMware Workstation
PowerFlex Appliance
PowerFlex rack
How to mitigate CVE-2025-22224
IBM Cloud Pak System - update to 2.3.6.0
VMware Workstation - update to 17.6.3
PowerFlex Appliance - update to IC-38.367.01
PowerFlex rack - update to 3.6.7.1