CVE-2025-22225
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.
CISA KEV
- Vendor
- VMware
- Product
- ESXi
- Due date
- 2025-03-25
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390 ; https://nvd.nist.gov/vuln/detail/CVE-2025-22225
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.