
🚨 CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks Source: https://cybersecuritynews.com/vmware-esxi-0-day-ransomware-attack/ CISA recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability. This flaw, patched by Broadcom in March 2025, enables attackers to escape virtual machine isolation and deploy ransomware across hypervisors. CVE-2025-22225 is an arbitrary write vulnerability in VMware ESXi, rated Important with a CVSS score of 8.2. A malicious actor with privileges in the VMX process can trigger an arbitrary kernel write, breaking out of the sandbox to gain hypervisor control. #cybersecurityNews #Vulnerability
Post summary
CISA confirms active exploitation of CVE-2025-22225, a VMware ESXi sandbox escape flaw, in ransomware attacks, and notes the March 2025 patch from Broadcom.


















