VMware ESXi 3-CVE Zero-Day Chain — VMCI Heap-Overflow + Sandbox Escape + HGFS Info Leak (VMSA-2025-0004, Active Ransomware) — Threadlinqs Intelligence
As of 2026-05-30, VMware ESXi 3-CVE Zero-Day Chain — VMCI Heap-Overflow + Sandbox Escape + HGFS Info Leak (VMSA-2025-0004, Active Ransomware) is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-0093 · Severity: CRITICAL · Status: ACTIVE · Category: VULNERABILITY
Attribution: N/A · FINANCIAL
VMSA-2025-0004 documents three critical VMware zero-day vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) in ESXi, Workstation, and Fusion — all confirmed exploited in the wild and used
VMware ESXi is the dominant enterprise hypervisor with an estimated 500,000+ installations worldwide running critical workloads. VMSA-2025-0004 disclosed three zero-day vulnerabilities that, when chained, enable complete VM-to-hypervisor escape — the most catastrophic attack scenario in virtualized environments.
**CVE-2025-22224 — VMCI Heap-Overflow (CVSS 9.3, Critical)**
A Time-of-Check Time-of-Use (TOCTOU) vulnerability in VMware's VMCI (Virtual Machine Communication Interface) leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. This is the initial entry point in the exploitation chain — from VM admin to VMX process execution on the hypervisor host.
**CVE-2025-22225 — ESXi Arbitrary Write / Sandbox Escape (CVSS 8.2, Important)**
An arbitrary write vulnerability in VMware ESXi. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. This is the pivotal vulnerability in the chain — once the attacker has VMX process execution (via CVE-2025-22224), CVE-2025-22225 enables full sandbox escape to the ESXi kernel, achieving hypervisor-level code execution.
**CVE-2025-22226 — HGFS Information Disclosure (CVSS 7.1, Important)**
An out-of-bounds read in HGFS (Host-Guest File System) allows a malicious actor with VM administrative privileges to leak memory from the VMX process. This vulnerability enables information disclosure that aids exploitation of the other two CVEs — leaking memory layouts, ASLR bypasses, and kernel pointers needed for reliable exploitation.
**Attack Chain:**
1. Attacker gains administrative access to a virtual machine (via initial access — phishing, web exploitation, stolen credentials)
2. CVE-2025-22226 (HGFS info leak) — Leak VMX process memory to map address space and defeat ASLR
3. CVE-2025-22224 (VMCI heap overflow) — Exploit TOCTOU to achieve code execution as the VMX process on the host
4. CVE-2025-22225 (ESXi arbitrary write) — Escape the VMX sandbox to achieve kernel-level execution on ESXi hypervisor
5. Full hypervisor compromise — access to ALL virtual machines, vCenter, storage, and bare-metal resources
6. Ransomware deployment — encrypt VM datastores (VMFS/NFS), lock out vCenter, ransom the entire virtualized infrastructure
All three vulnerabilities were discovered and reported by Microsoft Threat Intelligence Center (MSTIC), which indicates they were found during investigation of active exploitation by threat actors. VMware (Broadcom) confirmed in-the-wild exploitation in the advisory. CISA added all three to the Known Exploited Vulnerabilities catalog on March 4, 2025 — the same day as the advisory — with a 21-day remediation deadline (March 25, 2025), explicitly noting use in ransomware campaigns.
The ransomware implications are extreme: a single compromised VM can be leveraged to encrypt every VM on the hypervisor host, across all datastores, without triggering guest-level security tools. ESXi ransomware (e.g., ESXiArgs, Royal ESXi variant, Black Basta ESXi) has historically targeted SSH/OpenSLP vulnerabilities — this chain provides a fundamentally new attack surface from inside the VM.
Weaknesses (CWE)
CWE-367, CWE-787, CWE-125
Target sectors: All sectors using VMware ESXi, Data Centers, Cloud Service Providers, Enterprise IT, Healthcare, Financial, Government
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2025-22224, CVE-2025-22225, CVE-2025-22226, T1203, T1068, T1611, T1211, T1082, T1497, T1210, T1213, T1486, T1489