New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Broadcom / VMWare vulnerable: CVE-2025-22224 9.3 / CVE-2025-22225 8.2 / CVE-2025-22226 7.1
Quite interesting writeup: https://doublepulsar.com/use-one-virtual-machine-to-own-them-all-active-exploitation-of-esxicape-0091ccc5bdfc
I heard that it is already exploited in the wild

Comments
"Currently the exploit isn’t ‘public’, in that it isn’t on Github and nobody has released a write up from reversing the patch. This gives a window to patch before more details become public."
Relax. VMware is paid well, patch will be released before your low end infra gets hit.
Amazing! Owner of one is owner of all.