CVE-2025-22224Active Exploitation(vmware / cloud_foundation)

HIGHCVSS 8.2 · HIGHCISA KEV

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch vmware cloud_foundation systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

6.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-25. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-367

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_foundation
  • esxi
  • telco_cloud_infrastructure
  • telco_cloud_platform

Threat summary

  • Active exploitation appears in 7 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days

What's happening

  • Active exploitation reported across 7 signals
  • Exploit tool or code specified in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Peaked 4d ago at 4 mentions (2026-02-05); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
cloud_foundationesxitelco_cloud_infrastructuretelco_cloud_platformworkstation

11 versions affected across 5 products

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-02-05: 4Mentions · 2026-02-06: 1Mentions · 2026-02-12: 1Mentions · 2026-02-17: 1Mentions · 2026-09-25: 1Exploit Tool / Code · 2026-02-05: 2Active Exploitation · 2026-02-05: 3Active Exploitation · 2026-02-06: 1Active Exploitation · 2026-02-12: 1Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-09-25: 1Patch / Workaround · 2026-02-05: 3Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-09-25: 1Technical Details · 2026-02-05: 4Technical Details · 2026-02-06: 1Technical Details · 2026-02-12: 1Technical Details · 2026-09-25: 102-0502-0602-1202-1709-25
Signal classification3 categories
Active Exploitation
675.0%
Exploit
112.5%
Patch
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-054
Active Exploitation2Exploit1Patch1
2026-02-061
Active Exploitation1
2026-02-121
Active Exploitation1
2026-02-171
Active Exploitation1
2026-09-251
Active Exploitation1
Full discourse8 posts
  • iototsecnews@iototsecnews
    Active Exploitation

    VMware ESXi の脆弱性 CVE-2025-22224/22225/22226:ランサムウェアによる悪用を CISA が確認 https://iototsecnews.jp/2026/02/05/cisa-warns-of-vmware-esxi-0-day-vulnerability-exploited-in-ransomware-attacks/ VMware ESXi における深刻な脆弱性が、ランサムウェア攻撃で悪用されていると、CISA が警告を出しています。この問題の原因は、ハイパーバイザのメモリ管理に関する設計上の不備にあります。具体的には、脆弱性 CVE-2025-22225 を悪用することで、仮想マシンのサンドボックスを突破し、管理下の全システムを制御するハイパーバイザへ直接アクセスできてしまう “VMエスケープ” が可能になってしまいます。この不備に加えて、管理者権限の不適切な運用や、CVE-2025-22224 などの複数の欠陥を組み合わせる攻撃手法により、本来守られるべき仮想マシン同士の境界が無効化されます。現在も、パッチ未適用のシステムが存在し、この攻撃の潜在的な標的にされていると、CISA は注意を促しています。 #CISA #CVE202522224 #CVE202522225 #CVE202522226 #ESXi #Exploit #Government #KEV #VMware #Vulnerability

    Post summary

    VMware ESXi CVE‑2025‑22224/22225/22226 are actively exploited by ransomware, as confirmed by a CISA warning, with detailed information about VM escape and hypervisor memory management flaws.

    01000192
    483 followersView on X
  • Alkor Files@AlkorFiles
    Exploit

    3/8 VMware ESXi: "ESXicape" zero-day. 30k+ instancias en riesgo. Exploit cadena (CVE-2025-22224/25/26) escapa VM al hypervisor con backdoor VSOCKpuppet. Invisible a monitors de red. ¿Tu cloud virtual está comprometido?

    Post summary

    The post warns that VMware ESXi has a zero‑day (CVE‑2025‑22224/25/26) allowing a VM escape to the hypervisor via a VSOCKpuppet backdoor, potentially affecting 30k+ instances and bypassing network monitoring.

    1000040
    20 followersView on X
  • ngCERT@ngCERTofficial
    Active Exploitation

    🚨 CRITICAL VMware Workstation & Fusion vulnerabilities (CVE-2025-22224 & CVE-2025-22226) are actively exploited in the wild. Host systems are subject to VM escape & code execution attacks. Patch immediately. Find out more on our website https://cert.gov.ng/advisories/critical-vulnerabilities-in-vmware-workstation-and-fusion #VMware #CyberSecurity #CVE202522224

    Post summary

    CERT-NG warns that CVE-2025-22224 and CVE-2025-22226 in VMware Workstation and Fusion are actively exploited in the wild for VM escape and code execution, urging immediate patching.

    00000142
    1.4K followersView on X
  • Mockun@Mockun45
    Active Exploitation

    VMware ESXi の脆弱性 CVE-2025-22224/22225/22226:ランサムウェアによる悪用を CISA が確認 https://iototsecnews.jp/2026/02/05/cisa-warns-of-vmware-esxi-0-day-vulnerability-exploited-in-ransomware-attacks/

    Post summary

    CISA confirms that VMware ESXi vulnerabilities CVE‑2025‑22224/22225/22226 are actively exploited in ransomware attacks.

    00000112
    147 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Confirms Ransomware Actors Are Exploiting VMware ESXi Sandbox-Escape CVE-2025-22225 CISA confirmed CVE-2025-22225 (VMware ESXi sandbox escape) is being used in ransomware attacks nearly a year after it entered the KEV catalog, with details withheld—reinforcing that unpatched ESXi remains a high-value foothold for rapid domain-wide impact. Huntress also warned of real-world chaining with CVE-2025-22224/22226 (patched March 2025), so immediate patch validation and exposure reduction are critical. 🎯 Target: Global/VMware ESXi & Virtualization #️⃣ Category: #Vulnerability #CyberCrime #BlueTeam 🔗 URL: https://www.scworld.com/brief/cisa-ransomware-intrusions-exploiting-vmware-esxi-bug-ongoing

    Post summary

    CISA confirms ransomware actors are actively exploiting VMware ESXi sandbox‑escape CVE‑2025‑22225, highlighting the urgency of patching unpatched systems, while Huntress notes real‑world chaining with related CVEs.

    0000074
    191 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Flags VMware ESXi CVE-2025-22225 as Ransomware-Exploited After Huntress Links It to Zero-Day Exploit Toolkit CISA updated KEV to confirm ransomware actors are exploiting VMware ESXi arbitrary-write flaw CVE-2025-22225 (patched March 2025), with researchers tying real-world exploitation to a toolkit likely chaining the related zero-day trio (CVE-2025-22224/22225/22226) for info leak + memory corruption and escape. Prioritize patching ESXi/Workstation/Fusion immediately—KEV is already a lagging indicator and this is now actively abused. 🎯 Target: Global/Virtualization & Data Centers #️⃣ Category: #Vulnerability #CyberCrime #BlueTeam 🔗 URL: https://www.helpnetsecurity.com/2026/02/05/cisa-cve-2025-22225-ransomware-exploitation/

    Post summary

    CISA confirms that VMware ESXi CVE-2025-22225 is actively exploited by ransomware actors using a zero‑day toolkit, with a patch available and urgent patching urged.

    0000049
    192 followersView on X
  • Jeff Hall - PCI Guru - #StandWithUkraine@jbhall56
    Patch

    Broadcom patched this ESXi arbitrary-write vulnerability (tracked as CVE-2025-22225) almost one year ago, in March 2025, alongside a memory leak (CVE-2025-22226) and a TOCTOU flaw (CVE-2025-22224), and tagged them all as actively exploited zero-days. https://www.bleepingcomputer.com/news/security/cisa-vmware-esxi-flaw-now-exploited-in-ransomware-attacks/

    Post summary

    Broadcom released a patch for CVE-2025-22225 in March 2025, while the vulnerability and related flaws were acknowledged as actively exploited zero‑days in the wild.

    00000127
    909 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA: VMware ESXi “0-day” (CVE-2025-22225) now exploited by ransomware crews for hypervisor takeover CISA says ransomware actors are actively exploiting CVE-2025-22225 (ESXi VMX sandbox escape via arbitrary kernel write), typically chained with CVE-2025-22224/22226 to break VM isolation and gain hypervisor-level control for fleet-wide ransomware deployment. Defenders should urgently patch ESXi 7/8, restrict VMX/VM admin privileges, and hunt for signs of driver abuse, VMCI tampering, and hypervisor backdoors (e.g., VSOCK-based persistence). 🕷️ Malware: MAESTRO (exploit toolkit) / VSOCKpuppet (backdoor) 🎯 Target: Global/Enterprise (VMware ESXi Hypervisors) #️⃣ Category: #Vulnerability #CyberCrime #BlueTeam 🔗 URL: https://cybersecuritynews.com/vmware-esxi-0-day-ransomware-attack/

    Post summary

    CISA reports that ransomware operators are actively exploiting CVE‑2025‑22225 on VMware ESXi hypervisors, using tools such as MAESTRO and VSOCKpuppet to achieve hypervisor takeover and fleet‑wide ransomware deployment.

    0000086
    192 followersView on X
CPE platform detail56 entries

56 of 56 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarecloud_foundation---
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
Appvmwaretelco_cloud_infrastructure2.2--
Appvmwaretelco_cloud_infrastructure2.5--
Appvmwaretelco_cloud_infrastructure2.7--
Appvmwaretelco_cloud_infrastructure3.0--
Appvmwaretelco_cloud_platform2.0--
Appvmwaretelco_cloud_platform2.5--
Appvmwaretelco_cloud_platform2.7--
Appvmwaretelco_cloud_platform3.0--
Appvmwaretelco_cloud_platform4.0--
Appvmwaretelco_cloud_platform4.0.1--
Appvmwaretelco_cloud_platform5.0--
Appvmwareworkstation---

Explore more