Threat reportVulnerabilityTL-2026-0093

VMware ESXi 3-CVE Zero-Day Chain — VMCI Heap-Overflow + Sandbox Escape + HGFS Info Leak (VMSA-2025-0004, Active Ransomware)

criticalACTIVE

VMware ESXi 3-CVE Zero-Day Chain (TL-2026-0093) is a critical-severity software vulnerability, first published 2026-02-16. It has no confirmed attribution, references 3 CVEs (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226), maps to 20 MITRE ATT&CK techniques (T1003, T1005, T1068), and is covered by 9 detection rules and 25 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
3Referenced vulnerabilities
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-0093

Threat ID
TL-2026-0093
Severity
CRITICAL
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
All sectors using VMware ESXi, Data Centers, Cloud Service Providers, Enterprise IT, Healthcare, Financial, Government
Target regions
Global
Detection rules
9
Indicators of compromise
25

How VMware ESXi 3-CVE Zero-Day Chain works

VMSA-2025-0004 documents three critical VMware zero-day vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) in ESXi, Workstation, and Fusion — all confirmed exploited in the wild and used in ransomware campaigns. CVE-2025-22225 (CVSS 8.2) is an arbitrary write vulnerability in VMware ESXi that enables sandbox escape: an attacker with privileges within the VMX process can trigger an arbitrary kernel write to escape VM isolation and execute code on the hypervisor. CVE-2025-22224 (CVSS 9.3) is a TOCTOU heap-overflow in VMCI enabling VM-to-host code execution. CVE-2025-22226 (CVSS 7.1) is an HGFS out-of-bounds read for information disclosure. All three were reported by Microsoft Threat Intelligence Center (MSTIC) and chained for full VM escape → hypervisor compromise → bare-metal ransomware deployment. CISA added all three to KEV on March 4, 2025 with a remediation deadline of March 25, 2025.

VMware ESXi is the dominant enterprise hypervisor with an estimated 500,000+ installations worldwide running critical workloads. VMSA-2025-0004 disclosed three zero-day vulnerabilities that, when chained, enable complete VM-to-hypervisor escape — the most catastrophic attack scenario in virtualized environments.

**CVE-2025-22224 — VMCI Heap-Overflow (CVSS 9.3, Critical)** A Time-of-Check Time-of-Use (TOCTOU) vulnerability in VMware's VMCI (Virtual Machine Communication Interface) leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. This is the initial entry point in the exploitation chain — from VM admin to VMX process execution on the hypervisor host.

**CVE-2025-22225 — ESXi Arbitrary Write / Sandbox Escape (CVSS 8.2, Important)** An arbitrary write vulnerability in VMware ESXi. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. This is the pivotal vulnerability in the chain — once the attacker has VMX process execution (via CVE-2025-22224), CVE-2025-22225 enables full sandbox escape to the ESXi kernel, achieving hypervisor-level code execution.

**CVE-2025-22226 — HGFS Information Disclosure (CVSS 7.1, Important)** An out-of-bounds read in HGFS (Host-Guest File System) allows a malicious actor with VM administrative privileges to leak memory from the VMX process. This vulnerability enables information disclosure that aids exploitation of the other two CVEs — leaking memory layouts, ASLR bypasses, and kernel pointers needed for reliable exploitation.

**Attack Chain:** 1. Attacker gains administrative access to a virtual machine (via initial access — phishing, web exploitation, stolen credentials) 2. CVE-2025-22226 (HGFS info leak) — Leak VMX process memory to map address space and defeat ASLR 3. CVE-2025-22224 (VMCI heap overflow) — Exploit TOCTOU to achieve code execution as the VMX process on the host 4. CVE-2025-22225 (ESXi arbitrary write) — Escape the VMX sandbox to achieve kernel-level execution on ESXi hypervisor 5. Full hypervisor compromise — access to ALL virtual machines, vCenter, storage, and bare-metal resources 6. Ransomware deployment — encrypt VM datastores (VMFS/NFS), lock out vCenter, ransom the entire virtualized infrastructure

All three vulnerabilities were discovered and reported by Microsoft Threat Intelligence Center (MSTIC), which indicates they were found during investigation of active exploitation by threat actors. VMware (Broadcom) confirmed in-the-wild exploitation in the advisory. CISA added all three to the Known Exploited Vulnerabilities catalog on March 4, 2025 — the same day as the advisory — with a 21-day remediation deadline (March 25, 2025), explicitly noting use in ransomware campaigns.

The ransomware implications are extreme: a single compromised VM can be leveraged to encrypt every VM on the hypervisor host, across all datastores, without triggering guest-level security tools. ESXi ransomware (e.g., ESXiArgs, Royal ESXi variant, Black Basta ESXi) has historically targeted SSH/OpenSLP vulnerabilities — this chain provides a fundamentally new attack surface from inside the VM.

MITRE ATT&CK techniques used in TL-2026-0093

credential-access

T1003 OS Credential Dumping

collection

T1005 Data from Local System; T1213 Data from Information Repositories

privilege-escalation

T1068 Exploitation for Privilege Escalation; T1611 Escape to Host

command-and-control

T1071.001 Web Protocols

discovery

T1082 System Information Discovery

persistence

T1098 Account Manipulation; T1505 Server Software Component

initial-access

T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment

execution

T1203 Exploitation for Client Execution

lateral-movement

T1210 Exploitation of Remote Services

defense-evasion

T1211 Exploitation for Stealth; T1497 Virtualization/Sandbox Evasion

impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery

defense-impairment

T1685 Disable or Modify Tools; T1685.006 Clear Linux or Mac System Logs

Remediation for VMware ESXi 3-CVE Zero-Day Chain

Patches

  • ESXi 8.0: ESXi80U3d-24585383 and ESXi80U2d-24585300 (March 4, 2025)
  • ESXi 7.0: ESXi70U3s-24585291 (March 4, 2025)
  • VMware Workstation 17.6.3 (March 4, 2025)
  • VMware Fusion 13.6.3 (March 4, 2025)
  • Cloud Foundation: Async patch via KB88287
  • Telco Cloud: KB389385

Immediate actions

  • Apply ESXi patches IMMEDIATELY — CVE-2025-22224/22225/22226 are actively exploited in ransomware campaigns
  • ESXi 8.0: Apply ESXi80U3d-24585383 or ESXi80U2d-24585300
  • ESXi 7.0: Apply ESXi70U3s-24585291
  • VMware Workstation: Update to 17.6.3
  • VMware Fusion: Update to 13.6.3
  • VMware Cloud Foundation: Apply async patch per KB88287
  • Restrict VM administrative access — the attack chain requires VM admin privileges as the entry point
  • Monitor ESXi host logs for anomalous VMX process behavior and kernel writes

Workarounds

  • No workarounds available per VMware/Broadcom advisory — patching is the only remediation
  • Risk reduction: restrict VM admin access, disable unnecessary VMCI/HGFS features where possible

Longer-term hardening

  • Implement network segmentation isolating ESXi management interfaces from general network access
  • Enable VMware vSphere Trust Authority for attestation-based ESXi host validation
  • Deploy syslog forwarding from ESXi hosts to SIEM for centralized monitoring
  • Implement immutable ESXi configurations via vLCM (vSphere Lifecycle Manager)
  • Review and restrict VMCI and HGFS access where not required
  • Deploy EDR solutions with hypervisor-level visibility (e.g., VMware NSX, Carbon Black for Cloud)
  • Maintain offline backups of VM datastores disconnected from vCenter/ESXi

CVEs associated with VMware ESXi 3-CVE Zero-Day Chain

CVE-2025-22224, CVE-2025-22225, CVE-2025-22226

Weaknesses (CWE) in VMware ESXi 3-CVE Zero-Day Chain

CWE-367, CWE-787, CWE-125

Timeline of VMware ESXi 3-CVE Zero-Day Chain

  • Microsoft Threat Intelligence Center (MSTIC) credited with discovery of all three vulnerabilities. Discovery during active threat investigation indicates MSTIC found these while investigating real-world exploitation by threat actors.
  • CISA adds all three CVEs to Known Exploited Vulnerabilities catalog. CVE-2025-22225 explicitly noted as 'Known to be used in ransomware campaigns.' Remediation deadline: March 25, 2025 (21 days). Source: CISA KEV
  • VMware releases patches for all affected products: ESXi 8.0 (ESXi80U3d-24585383, ESXi80U2d-24585300), ESXi 7.0 (ESXi70U3s-24585291), Workstation 17.6.3, Fusion 13.6.3. No workarounds available. Source: VMSA-2025-0004
  • Broadcom publishes VMSA-2025-0004 disclosing three critical VMware vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) in ESXi, Workstation, and Fusion. All three confirmed exploited in the wild. Credited to Microsoft Threat Intelligence Center. Source: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390
  • Security community responds with emergency patching advisories. VMware ESXi's dominance in enterprise virtualization (estimated 500,000+ installations) makes this a global-scale emergency. Ransomware groups expected to weaponize rapidly.
  • CISA BOD 22-01 remediation deadline for CVE-2025-22224, CVE-2025-22225, CVE-2025-22226. Federal agencies required to have patches applied or discontinue use of affected products.
  • As of 2026-05-29, the VMSA-2025-0004 ESXi 3-CVE chain remains actively exploited: CISA flagged CVE-2025-22225 as ransomware-used in its 2026-02-05 KEV update and SC Media reports intrusions ongoing. Patches exist (no workaround), but Huntress's Jan 2026 MAESTRO/VSOCKpuppet toolkit confirms all 3 CVEs are still weaponized in the wild against unpatched hypervisors.

Sources cited for VMware ESXi 3-CVE Zero-Day Chain

Detection coverage for TL-2026-0093

As of 2026-02-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0093 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats