CVE-2025-22225: VMware ESXi Arbitrary Write Vulnerability
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
Other sources
VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of VMware ESXi and Horizon DaaS if mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-22225?
CVE-2025-22225 is considered a high severity vulnerability due to its potential for arbitrary kernel writes.
How do I mitigate CVE-2025-22225?
To mitigate CVE-2025-22225, ensure that VMware ESXi is updated to the latest security patch provided by VMware.
Who is affected by CVE-2025-22225?
CVE-2025-22225 affects users of VMware ESXi who have configured permissions that allow access to the VMX process.
What type of vulnerability is CVE-2025-22225?
CVE-2025-22225 is classified as an arbitrary write vulnerability, which may lead to a sandbox escape.
Can CVE-2025-22225 allow a malicious actor to escalate privileges?
Yes, CVE-2025-22225 can potentially allow a malicious actor to escalate privileges within the affected system.