imPC@ndo IT

Tracker / CVE-2025-22224

CVE-2025-22224

Exploited Critical 9.3

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

Affected products and versions

vmware cloud_foundation
vmware esxi
vmware telco_cloud_infrastructure
vmware telco_cloud_platform
vmware workstation · 17.0 → 17.6.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References