CVE-2025-22226: VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
Other sources
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
VMware ESXifrom your environment.Discontinue use of the product if mitigations are unavailable.
- Remove
Remove
Horizon DaaSfrom your environment.Discontinue use of the product if mitigations are unavailable.
- Remove
Remove
VMware Fusionfrom your environment.Discontinue use of the product if mitigations are unavailable.
- Remove
Remove
VMware Workstationfrom your environment.Discontinue use of the product if mitigations are unavailable.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-22226?
CVE-2025-22226 is considered a critical vulnerability that can lead to information disclosure.
How do I fix CVE-2025-22226?
To mitigate CVE-2025-22226, update to the latest patched version of VMware ESXi, Workstation, or Fusion as recommended by VMware.
Who is affected by CVE-2025-22226?
CVE-2025-22226 affects users of VMware ESXi, Workstation, and Fusion who have administrative privileges to a virtual machine.
What type of vulnerability is CVE-2025-22226?
CVE-2025-22226 is an information disclosure vulnerability caused by an out-of-bounds read in the HGFS component.
Can CVE-2025-22226 be exploited remotely?
No, CVE-2025-22226 requires administrative access to a vulnerable virtual machine for exploitation.