← All CVEs

CVE-2025-22226

high · 7.1Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added 2025-03-04Remediation due 2025-03-25

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

7.1
CVSS
1.7%
EPSS (exploit prob.)
77th
EPSS percentile
2025-03-04
Published

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Weaknesses

CWE-125

Affected products

VendorProductAffected versions
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi7.0
vmwareesxi8.0
vmwareesxi8.0
vmwareesxi8.0
vmwareesxi8.0
vmwareesxi8.0
vmwareesxi8.0
vmwareesxi8.0
vmwareesxi8.0
vmwareesxi8.0
vmwareesxi8.0
vmwareesxi8.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-22226