CVE-2025-22224: VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.
Other sources
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services to mitigate risks from the VMware ESXi/Workstation TOCTOU race condition vulnerability.
- Compensating control
Discontinue use of the affected product(s) (VMware ESXi, Horizon DaaS, and VMware Workstation) if vendor-provided mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-22224?
CVE-2025-22224 is rated as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-22224?
To mitigate CVE-2025-22224, update VMware ESXi and Workstation to the latest versions provided by VMware.
Who is affected by CVE-2025-22224?
CVE-2025-22224 affects users with local administrative privileges on VMware ESXi and Workstation.
What type of vulnerability is CVE-2025-22224?
CVE-2025-22224 is a TOCTOU (Time-of-Check Time-of-Use) vulnerability leading to out-of-bounds write.
What could an attacker do by exploiting CVE-2025-22224?
An attacker exploiting CVE-2025-22224 could execute arbitrary code as the virtual machine's VMX process on the host.