Permissions, Privileges, and Access Controls in VMware ESXi - CVE-2025-22225

 

Permissions, Privileges, and Access Controls in VMware ESXi - CVE-2025-22225

Published: March 4, 2025


Vulnerability identifier: #VU105279
CSH Severity: High
CVSS v4: 6.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2025-22225
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improperly imposed security restrictions. A malicious guest with access to the VMX process can write arbitrary data to kernel and bypass sandbox restrictions. 

Note, the vulnerability is being actively exploited in the wild.


Affected software

VMware ESXi
IBM Cloud Pak System
PowerFlex Appliance
PowerFlex rack

How to mitigate CVE-2025-22225

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi80U2d-24585300, ESXi70U3s-24585291, ESXi80U3d-24585383
IBM Cloud Pak System - update to 2.3.6.0
PowerFlex Appliance - update to IC-38.367.01
PowerFlex rack - update to 3.6.7.1

External References

Related Security Bulletins