Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Mar 25, 2025

CVE-2025-22225

High
EPSS 6.1%CISA KEVRansomware
VMware/ESXi

Description

VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.

EPSS — Exploit Probability

6.1%

Higher than 90.7% of all CVEs

Required Action

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390 ; https://nvd.nist.gov/vuln/detail/CVE-2025-22225

Risk Assessment

HIGH
In CISA KEV
Ransomware

Details

Severity
High
EPSS
6.1%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Mar 4, 2025

Added to KEV

Mar 4, 2025

Remediation Due

Mar 25, 2025

Affected Product

VMware

ESXi

View all VMware CVEs