TecnoArtesanos Tech BlogTecnoArtesanos Tech Blog

Blog

0
Sergio Morales
Thursday, 06 March 2025 / Published in Uncategorized

Critical Zero-Day Vulnerabilities Found in These VMware Products

Broadcom has patched three actively exploited zero-day vulnerabilities in VMware ESXi, Workstation, and Fusion, discovered by Microsoft’s Threat Intelligence Center. The flaws, which were being leveraged in real-world attacks at the time of discovery, could allow attackers with administrator or root access to a virtual machine to breach the underlying hypervisor, potentially exposing all connected VMs and sensitive data.

Contents
  • How do these vulnerabilities work?
    • Must-read security coverage
  • Which products are affected?

How do these vulnerabilities work?

If a threat actor gains administrative access to a virtual machine’s guest OS, they can escalate privileges and break into the hypervisor. Once inside, they could manipulate or access other virtual machines running on the same hypervisor, posing a significant security risk.

The three vulnerabilities are:

  • CVE-2025-22224: A Time-of-Check Time-of-Use (TOCTOU) vulnerability in VMware ESXi and Workstation which can lead to an out-of-bounds write condition if an attacker already has admin privileges.
  • CVE-2025-22225: An arbitrary write vulnerability in VMware ESXi.
  • CVE-2025-22226: An information disclosure vulnerability in VMware ESXi, Workstation, and Fusion that could be used to leak memory.

To remediate the vulnerabilities, customers should apply the patches found in Broadcom’s notification. All versions of VMware ESX, VMware vSphere, VMware Cloud Foundation, or VMware Telco Cloud Platform are affected, except those with the newest update.

SEE: Google Chrome’s switch to Manifest V3 continues to break ad blockers such as uBlock Origin.

Must-read security coverage

Which products are affected?

The following products are affected by all three CVEs (via Rapid7):

  • Broadcom VMware ESXi 7.0 and 8.0.
  • Broadcom VMware Cloud Foundation 4.5.x and 5.x.
  • Broadcom VMware Telco Cloud Platform 5.x, 4.x, 3.x, and 2.x.
  • Broadcom VMware Telco Cloud Infrastructure 3.x and 2.x.

The following product is vulnerable to CVE-2025-22224 and CVE-2025-22226 specifically:

  • Broadcom VMware Workstation 17.x.

The following product is vulnerable to CVE-2025-22226 specifically:

  • Broadcom VMware Fusion 13.x.

VMware’s Live Patch feature will not apply the patches automatically in this case.

VMware Cloud Foundation Operations, Automation, Aria Suite, and VMware NSX are not affected.

Last year, VMware ESXi servers were hit by a double-extortion ransomware variant, with the threat actors impersonating a real organization.

What you can read next

Microsoft’s OneGov Deal Brings $6B+ in Federal Cloud Discounts
Las ventas de los vehículos eléctricos en EE UU podrían caer hacia 2026
AstraZeneca anuncia inversión de $600 millones de pesos en Guadalajara, el Silicon Valley mexicano

Recent Posts

  • Los agentes de IA rebeldes no son malvados, solo quieren complacernos
  • Dime cómo prompteas y la IA te dirá quién eres
  • La primicia ahora la tienen los periodistas de IA. Spoiler: son malos reporteros
  • El reto de las empresas mexicanas ya no es la adopción de IA, sino aprender a aprovecharla
  • Bienvenidos a la era de la computación hecha con cerebros de verdad

Recent Comments

  1. A WordPress Commenter on Welcome to My Tech Blog – A New Chapter in Innovation

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • August 2016

Categories

  • Uncategorized

Recent Posts

  • Los agentes de IA rebeldes no son malvados, solo quieren complacernos

    Que los agentes de IA vayan libres hackeando ot...
  • Dime cómo prompteas y la IA te dirá quién eres

    A finales de 2022, cuando OpenAI lanzó ChatGPT,...
  • La primicia ahora la tienen los periodistas de IA. Spoiler: son malos reporteros

    En la conferencia de seguridad Black Hat celebr...
  • El reto de las empresas mexicanas ya no es la adopción de IA, sino aprender a aprovecharla

    La adopción de la inteligencia artificial (IA) ...
  • Bienvenidos a la era de la computación hecha con cerebros de verdad

    Te voy a contar un secreto. Cada célula de tu c...

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • August 2016

Categories

  • Uncategorized

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Kallyas

The #1 Multi-Purpose theme with a Powerful Visual Page Builder that you’ll actually enjoy.

Newsletter

 

sociall

 

Company

Customer

The #1 WordPress theme with a Powerful Visual Page Builder that you'll actually enjoy.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum.

Feed with such ID does not exist

Made with  ♥  by Hogash Studios. All Rights Reserved © 2016.

TOP