Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-22224

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.548
EPSS Ranking 97.9%
CVSS Severity
CVSS v3 Score 9.3
Proposed Action
VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.
Ransomware Campaign
Unknown
Products affected by CVE-2025-22224


Contact Us

Shodan ® - All rights reserved