Threat Intelligence / CVE / CVE-2025-22226
CVE-2025-22226
CISA KEVVMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
CVSS v3 vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Weaknesses (CWE)
CWE-125
Threats tracking this CVE
References
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-22226
Full detection coverage & IOCs for threats exploiting CVE-2025-22226 are available via the Threadlinqs MCP server (Purple tier). View plans →