Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Critical VMware Vulnerabilities (9.3)

Newest vulnerabilities allow code running inside a VM to escape the sandbox and access the hypervisor.

A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390

  • CVE-2025-22224, a heap overflow in the Virtual Machine Communication Interface, with a severity rating of 9.3 out of a possible 10
  • CVE-2025-22225, an arbitrary write vulnerability, with a severity of 8.2
  • CVE-2025-22226, an information-disclosure vulnerability in the host-guest file system, with a severity of 7.1

VMware warned Tuesday that it has evidence suggesting the vulnerabilities are already under active exploitation in the wild.

https://arstechnica.com/security/2025/03/vmware-patches-3-critical-vulnerabilities-in-multiple-product-lines/

Sign In or Register to comment.