Vulnerability Details CVE-2025-22226
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.047
EPSS Ranking 88.8%
CVSS Severity
CVSS v3 Score 7.1
Proposed Action
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.
Ransomware Campaign
Unknown
Products affected by CVE-2025-22226
-
cpe:2.3:a:vmware:cloud_foundation:-
-
cpe:2.3:a:vmware:fusion:13.0.0
-
cpe:2.3:a:vmware:fusion:13.0.1
-
cpe:2.3:a:vmware:fusion:13.0.2
-
cpe:2.3:a:vmware:fusion:13.5
-
cpe:2.3:a:vmware:fusion:13.5.1
-
cpe:2.3:a:vmware:fusion:13.5.2
-
cpe:2.3:a:vmware:fusion:13.6
-
cpe:2.3:a:vmware:fusion:13.6.1
-
cpe:2.3:a:vmware:fusion:13.6.2
-
cpe:2.3:a:vmware:telco_cloud_infrastructure:2.2
-
cpe:2.3:a:vmware:telco_cloud_infrastructure:2.5
-
cpe:2.3:a:vmware:telco_cloud_infrastructure:2.7
-
cpe:2.3:a:vmware:telco_cloud_infrastructure:3.0
-
cpe:2.3:a:vmware:telco_cloud_platform:2.0
-
cpe:2.3:a:vmware:telco_cloud_platform:2.5
-
cpe:2.3:a:vmware:telco_cloud_platform:2.7
-
cpe:2.3:a:vmware:telco_cloud_platform:3.0
-
cpe:2.3:a:vmware:telco_cloud_platform:4.0
-
cpe:2.3:a:vmware:telco_cloud_platform:4.0.1
-
cpe:2.3:a:vmware:telco_cloud_platform:5.0
-
cpe:2.3:a:vmware:workstation:17.0
-
cpe:2.3:a:vmware:workstation:17.0.0
-
cpe:2.3:a:vmware:workstation:17.0.1
-
cpe:2.3:a:vmware:workstation:17.0.2
-
cpe:2.3:a:vmware:workstation:17.5.0
-
cpe:2.3:a:vmware:workstation:17.5.1
-
cpe:2.3:a:vmware:workstation:17.5.2
-
cpe:2.3:a:vmware:workstation:17.6.0
-
cpe:2.3:a:vmware:workstation:17.6.1
-
cpe:2.3:a:vmware:workstation:17.6.2
-
cpe:2.3:o:vmware:esxi:7.0
-
cpe:2.3:o:vmware:esxi:8.0