Out-of-bounds read in VMware ESXi - CVE-2025-22226

 

Out-of-bounds read in VMware ESXi - CVE-2025-22226

Published: March 4, 2025 / Updated: March 4, 2025


Vulnerability identifier: #VU105280
CSH Severity: High
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N]
CVE-ID: CVE-2025-22226
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a malicious guest to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition in HGFS. A malicious guest can trigger an out-of-bounds read error and read contents of memory on the system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

VMware ESXi
IBM Cloud Pak System
VMware Fusion
VMware Workstation
PowerFlex Appliance
PowerFlex rack

How to mitigate CVE-2025-22226

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi80U2d-24585300, ESXi70U3s-24585291, ESXi80U3d-24585383
IBM Cloud Pak System - update to 2.3.6.0
VMware Fusion - update to 13.6.3
VMware Workstation - update to 17.6.3
PowerFlex Appliance - update to IC-38.367.01
PowerFlex rack - update to 3.6.7.1

External References

Related Security Bulletins