Heap-based buffer overflow in VMware ESXi - CVE-2025-22224

 

Heap-based buffer overflow in VMware ESXi - CVE-2025-22224

Published: March 4, 2025


Vulnerability identifier: #VU105278
CSH Severity: High
CVSS v4: 6.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2025-22224
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a malicious guest to execute arbitrary code on the hypervisor.

The vulnerability exists due to a boundary error in VMCI. A malicious guest with administrative privileges can trigger a heap-based buffer overflow and execute arbitrary code on the hypervisor in the context of VMX process.

Note, the vulnerability is being actively exploited in the wild.


Affected software

VMware ESXi
IBM Cloud Pak System
VMware Workstation
PowerFlex Appliance
PowerFlex rack

How to mitigate CVE-2025-22224

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi80U2d-24585300, ESXi70U3s-24585291, ESXi80U3d-24585383
IBM Cloud Pak System - update to 2.3.6.0
VMware Workstation - update to 17.6.3
PowerFlex Appliance - update to IC-38.367.01
PowerFlex rack - update to 3.6.7.1

External References

Related Security Bulletins