LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-22225: VMware ESXi Arbitrary Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 4, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 25, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-22225 to its Known Exploited Vulnerabilities catalog on Mar 4, 2025, with a federal patch deadline of Mar 25, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of…

CVE-2025-22225 is an arbitrary write vulnerability in VMware ESXi. An attacker who already has privileges inside the VMX process can trigger a write into kernel memory and break out of the sandbox that is meant to contain virtual-machine activity. Because the flaw can lead to hypervisor-level compromise and has been observed in ransomware operations, it matters to any organization that runs ESXi hosts.

Defenders should treat this as a high-priority sandbox-escape issue. Confirm every version, patch, and configuration detail against the official VMware advisory before taking action.

How it works

The weakness is classified as CWE-123 (write-what-where condition). In practical terms, the vulnerability allows an attacker who already controls code running inside the VMX process to force an arbitrary write into kernel memory. That write can alter critical kernel structures and thereby escape the isolation boundary that normally keeps guest activity from affecting the hypervisor or other guests.

No public exploit code or step-by-step mechanics are supplied here; the CISA summary simply states that successful exploitation produces an arbitrary kernel write and a sandbox escape. Attackers would first need to obtain privileges inside the VMX process—typically through a separate guest compromise or misconfiguration—before they can abuse this flaw. Exact trigger conditions and memory offsets must be verified against the vendor advisory.

Am I affected? How to find it in your systems

VMware ESXi is the bare-metal hypervisor that commonly underpins private-cloud, virtual-desktop, and server-virtualization estates. Inventory every ESXi host, including those managed by vCenter, nested under other hypervisors, or running in lab and DR environments.

If you operate ESXi as a cloud service, also follow the applicable BOD 22-01 guidance referenced by CISA.

How to remediate

Apply the vendor-supplied update that addresses CVE-2025-22225 as soon as it can be tested and staged. The CISA required action is explicit: apply mitigations per vendor instructions, follow BOD 22-01 for cloud services, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with layered compensating controls.

These steps lower risk but do not eliminate it; plan the permanent patch as soon as possible.

If your data may have been exposed

Because this vulnerability has known ransomware use, a successful escape can lead to full host compromise, lateral movement, data theft, or encryption of virtual disks. If you suspect exploitation, isolate affected hosts, preserve forensic images, and engage your incident-response process. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · ESXi
WeaknessCWE-123
Added to CISA KEVMar 4, 2025
Federal patch deadlineMar 25, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities