Threat reportVulnerabilityTL-2026-0093
VMware ESXi 3-CVE Zero-Day Chain — VMCI Heap-Overflow + Sandbox Escape + HGFS Info Leak (VMSA-2025-0004, Active Ransomware)
VMware ESXi 3-CVE Zero-Day Chain (TL-2026-0093) is a critical-severity software vulnerability, first published 2026-02-16. It has no confirmed attribution, references 3 CVEs (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226), maps to 20 MITRE ATT&CK techniques (T1003, T1005, T1068), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 20MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-0093
- Threat ID
- TL-2026-0093
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- All sectors using VMware ESXi, Data Centers, Cloud Service Providers, Enterprise IT, Healthcare, Financial, Government
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 25
How VMware ESXi 3-CVE Zero-Day Chain works
VMSA-2025-0004 documents three critical VMware zero-day vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) in ESXi, Workstation, and Fusion — all confirmed exploited in the wild and used in ransomware campaigns. CVE-2025-22225 (CVSS 8.2) is an arbitrary write vulnerability in VMware ESXi that enables sandbox escape: an attacker with privileges within the VMX process can trigger an arbitrary kernel write to escape VM isolation and execute code on the hypervisor. CVE-2025-22224 (CVSS 9.3) is a TOCTOU heap-overflow in VMCI enabling VM-to-host code execution. CVE-2025-22226 (CVSS 7.1) is an HGFS out-of-bounds read for information disclosure. All three were reported by Microsoft Threat Intelligence Center (MSTIC) and chained for full VM escape → hypervisor compromise → bare-metal ransomware deployment. CISA added all three to KEV on March 4, 2025 with a remediation deadline of March 25, 2025.
VMware ESXi is the dominant enterprise hypervisor with an estimated 500,000+ installations worldwide running critical workloads. VMSA-2025-0004 disclosed three zero-day vulnerabilities that, when chained, enable complete VM-to-hypervisor escape — the most catastrophic attack scenario in virtualized environments.
**CVE-2025-22224 — VMCI Heap-Overflow (CVSS 9.3, Critical)** A Time-of-Check Time-of-Use (TOCTOU) vulnerability in VMware's VMCI (Virtual Machine Communication Interface) leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. This is the initial entry point in the exploitation chain — from VM admin to VMX process execution on the hypervisor host.
**CVE-2025-22225 — ESXi Arbitrary Write / Sandbox Escape (CVSS 8.2, Important)** An arbitrary write vulnerability in VMware ESXi. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. This is the pivotal vulnerability in the chain — once the attacker has VMX process execution (via CVE-2025-22224), CVE-2025-22225 enables full sandbox escape to the ESXi kernel, achieving hypervisor-level code execution.
**CVE-2025-22226 — HGFS Information Disclosure (CVSS 7.1, Important)** An out-of-bounds read in HGFS (Host-Guest File System) allows a malicious actor with VM administrative privileges to leak memory from the VMX process. This vulnerability enables information disclosure that aids exploitation of the other two CVEs — leaking memory layouts, ASLR bypasses, and kernel pointers needed for reliable exploitation.
**Attack Chain:** 1. Attacker gains administrative access to a virtual machine (via initial access — phishing, web exploitation, stolen credentials) 2. CVE-2025-22226 (HGFS info leak) — Leak VMX process memory to map address space and defeat ASLR 3. CVE-2025-22224 (VMCI heap overflow) — Exploit TOCTOU to achieve code execution as the VMX process on the host 4. CVE-2025-22225 (ESXi arbitrary write) — Escape the VMX sandbox to achieve kernel-level execution on ESXi hypervisor 5. Full hypervisor compromise — access to ALL virtual machines, vCenter, storage, and bare-metal resources 6. Ransomware deployment — encrypt VM datastores (VMFS/NFS), lock out vCenter, ransom the entire virtualized infrastructure
All three vulnerabilities were discovered and reported by Microsoft Threat Intelligence Center (MSTIC), which indicates they were found during investigation of active exploitation by threat actors. VMware (Broadcom) confirmed in-the-wild exploitation in the advisory. CISA added all three to the Known Exploited Vulnerabilities catalog on March 4, 2025 — the same day as the advisory — with a 21-day remediation deadline (March 25, 2025), explicitly noting use in ransomware campaigns.
The ransomware implications are extreme: a single compromised VM can be leveraged to encrypt every VM on the hypervisor host, across all datastores, without triggering guest-level security tools. ESXi ransomware (e.g., ESXiArgs, Royal ESXi variant, Black Basta ESXi) has historically targeted SSH/OpenSLP vulnerabilities — this chain provides a fundamentally new attack surface from inside the VM.
MITRE ATT&CK techniques used in TL-2026-0093
credential-access
collection
T1005 Data from Local System; T1213 Data from Information Repositories
privilege-escalation
T1068 Exploitation for Privilege Escalation; T1611 Escape to Host
command-and-control
discovery
T1082 System Information Discovery
persistence
T1098 Account Manipulation; T1505 Server Software Component
initial-access
T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment
execution
T1203 Exploitation for Client Execution
lateral-movement
T1210 Exploitation of Remote Services
defense-evasion
T1211 Exploitation for Stealth; T1497 Virtualization/Sandbox Evasion
impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery
defense-impairment
T1685 Disable or Modify Tools; T1685.006 Clear Linux or Mac System Logs
Remediation for VMware ESXi 3-CVE Zero-Day Chain
Patches
- ESXi 8.0: ESXi80U3d-24585383 and ESXi80U2d-24585300 (March 4, 2025)
- ESXi 7.0: ESXi70U3s-24585291 (March 4, 2025)
- VMware Workstation 17.6.3 (March 4, 2025)
- VMware Fusion 13.6.3 (March 4, 2025)
- Cloud Foundation: Async patch via KB88287
- Telco Cloud: KB389385
Immediate actions
- Apply ESXi patches IMMEDIATELY — CVE-2025-22224/22225/22226 are actively exploited in ransomware campaigns
- ESXi 8.0: Apply ESXi80U3d-24585383 or ESXi80U2d-24585300
- ESXi 7.0: Apply ESXi70U3s-24585291
- VMware Workstation: Update to 17.6.3
- VMware Fusion: Update to 13.6.3
- VMware Cloud Foundation: Apply async patch per KB88287
- Restrict VM administrative access — the attack chain requires VM admin privileges as the entry point
- Monitor ESXi host logs for anomalous VMX process behavior and kernel writes
Workarounds
- No workarounds available per VMware/Broadcom advisory — patching is the only remediation
- Risk reduction: restrict VM admin access, disable unnecessary VMCI/HGFS features where possible
Longer-term hardening
- Implement network segmentation isolating ESXi management interfaces from general network access
- Enable VMware vSphere Trust Authority for attestation-based ESXi host validation
- Deploy syslog forwarding from ESXi hosts to SIEM for centralized monitoring
- Implement immutable ESXi configurations via vLCM (vSphere Lifecycle Manager)
- Review and restrict VMCI and HGFS access where not required
- Deploy EDR solutions with hypervisor-level visibility (e.g., VMware NSX, Carbon Black for Cloud)
- Maintain offline backups of VM datastores disconnected from vCenter/ESXi
CVEs associated with VMware ESXi 3-CVE Zero-Day Chain
Weaknesses (CWE) in VMware ESXi 3-CVE Zero-Day Chain
Timeline of VMware ESXi 3-CVE Zero-Day Chain
- Microsoft Threat Intelligence Center (MSTIC) credited with discovery of all three vulnerabilities. Discovery during active threat investigation indicates MSTIC found these while investigating real-world exploitation by threat actors.
- CISA adds all three CVEs to Known Exploited Vulnerabilities catalog. CVE-2025-22225 explicitly noted as 'Known to be used in ransomware campaigns.' Remediation deadline: March 25, 2025 (21 days). Source: CISA KEV
- VMware releases patches for all affected products: ESXi 8.0 (ESXi80U3d-24585383, ESXi80U2d-24585300), ESXi 7.0 (ESXi70U3s-24585291), Workstation 17.6.3, Fusion 13.6.3. No workarounds available. Source: VMSA-2025-0004
- Broadcom publishes VMSA-2025-0004 disclosing three critical VMware vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) in ESXi, Workstation, and Fusion. All three confirmed exploited in the wild. Credited to Microsoft Threat Intelligence Center. Source: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390
- Security community responds with emergency patching advisories. VMware ESXi's dominance in enterprise virtualization (estimated 500,000+ installations) makes this a global-scale emergency. Ransomware groups expected to weaponize rapidly.
- CISA BOD 22-01 remediation deadline for CVE-2025-22224, CVE-2025-22225, CVE-2025-22226. Federal agencies required to have patches applied or discontinue use of affected products.
- As of 2026-05-29, the VMSA-2025-0004 ESXi 3-CVE chain remains actively exploited: CISA flagged CVE-2025-22225 as ransomware-used in its 2026-02-05 KEV update and SC Media reports intrusions ongoing. Patches exist (no workaround), but Huntress's Jan 2026 MAESTRO/VSOCKpuppet toolkit confirms all 3 CVEs are still weaponized in the wild against unpatched hypervisors.
Sources cited for VMware ESXi 3-CVE Zero-Day Chain
- Broadcom VMSA-2025-0004: VMware ESXi/Workstation/Fusion Multiple Vulnerabilities
- NVD — CVE-2025-22225
- NVD — CVE-2025-22224
- NVD — CVE-2025-22226
- CISA KEV — CVE-2025-22225 (Known Ransomware, Due: March 25, 2025)
- VMSA-2025-0004 FAQ
- ESXi 8.0 U3d Release Notes
- ESXi 7.0 U3s Release Notes
- VCF Async Patching Guide (KB88287)
- MITRE ATT&CK — T1611: Escape to Host
Detection coverage for TL-2026-0093
As of 2026-02-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0093 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.