# VMware ESXi 3-CVE Zero-Day Chain — VMCI Heap-Overflow + Sandbox Escape + HGFS Info Leak (VMSA-2025-0004, Active Ransomware)

> VMSA-2025-0004 documents three critical VMware zero-day vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) in ESXi, Workstation, and Fusion — all confirmed exploited in the wild and used in ransomware campaigns. CVE-2025-22225 (CVSS 8.2) is an arbitrary write vulnerability in VMware ESXi that enables sandbox escape: an attacker with privileges within the VMX process can trigger an arbitrary kernel write to escape VM isolation and execute code on the hypervisor. CVE-2025-22224 (CVSS 9.3) is a TOCTOU heap-overflow in VMCI enabling VM-to-host code execution. CVE-2025-22226 (CVSS 7.1) is an HGFS out-of-bounds read for information disclosure. All three were reported by Microsoft Threat Intelligence Center (MSTIC) and chained for full VM escape → hypervisor compromise → bare-metal ransomware deployment. CISA added all three to KEV on March 4, 2025 with a remediation deadline of March 25, 2025.

- **Published:** 2026-02-16T05:24:13Z
- **Last reviewed:** 2026-02-16T05:24:13Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0093
- **ID:** TL-2026-0093
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-22224, CVE-2025-22225, CVE-2025-22226

## Description

VMware ESXi is the dominant enterprise hypervisor with an estimated 500,000+ installations worldwide running critical workloads. VMSA-2025-0004 disclosed three zero-day vulnerabilities that, when chained, enable complete VM-to-hypervisor escape — the most catastrophic attack scenario in virtualized environments.

**CVE-2025-22224 — VMCI Heap-Overflow (CVSS 9.3, Critical)**
A Time-of-Check Time-of-Use (TOCTOU) vulnerability in VMware's VMCI (Virtual Machine Communication Interface) leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. This is the initial entry point in the exploitation chain — from VM admin to VMX process execution on the hypervisor host.

**CVE-2025-22225 — ESXi Arbitrary Write / Sandbox Escape (CVSS 8.2, Important)**
An arbitrary write vulnerability in VMware ESXi. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. This is the pivotal vulnerability in the chain — once the attacker has VMX process execution (via CVE-2025-22224), CVE-2025-22225 enables full sandbox escape to the ESXi kernel, achieving hypervisor-level code execution.

**CVE-2025-22226 — HGFS Information Disclosure (CVSS 7.1, Important)**
An out-of-bounds read in HGFS (Host-Guest File System) allows a malicious actor with VM administrative privileges to leak memory from the VMX process. This vulnerability enables information disclosure that aids exploitation of the other two CVEs — leaking memory layouts, ASLR bypasses, and kernel pointers needed for reliable exploitation.

**Attack Chain:**
1. Attacker gains administrative access to a virtual machine (via initial access — phishing, web exploitation, stolen credentials)
2. CVE-2025-22226 (HGFS info leak) — Leak VMX process memory to map address space and defeat ASLR
3. CVE-2025-22224 (VMCI heap overflow) — Exploit TOCTOU to achieve code execution as the VMX process on the host
4. CVE-2025-22225 (ESXi arbitrary write) — Escape the VMX sandbox to achieve kernel-level execution on ESXi hypervisor
5. Full hypervisor compromise — access to ALL virtual machines, vCenter, storage, and bare-metal resources
6. Ransomware deployment — encrypt VM datastores (VMFS/NFS), lock out vCenter, ransom the entire virtualized infrastructure

All three vulnerabilities were discovered and reported by Microsoft Threat Intelligence Center (MSTIC), which indicates they were found during investigation of active exploitation by threat actors. VMware (Broadcom) confirmed in-the-wild exploitation in the advisory. CISA added all three to the Known Exploited Vulnerabilities catalog on March 4, 2025 — the same day as the advisory — with a 21-day remediation deadline (March 25, 2025), explicitly noting use in ransomware campaigns.

The ransomware implications are extreme: a single compromised VM can be leveraged to encrypt every VM on the hypervisor host, across all datastores, without triggering guest-level security tools. ESXi ransomware (e.g., ESXiArgs, Royal ESXi variant, Black Basta ESXi) has historically targeted SSH/OpenSLP vulnerabilities — this chain provides a fundamentally new attack surface from inside the VM.

## MITRE ATT&CK

- T1203 Exploitation for Client Execution
- T1068 Exploitation for Privilege Escalation
- T1611 Escape to Host
- T1211 Exploitation for Stealth
- T1082 System Information Discovery
- T1497 Virtualization/Sandbox Evasion
- T1210 Exploitation of Remote Services
- T1213 Data from Information Repositories
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1490 Inhibit System Recovery
- T1190 Exploit Public-Facing Application
- T1505 Server Software Component
- T1685 Disable or Modify Tools
- T1566.001 Spearphishing Attachment
- T1003 OS Credential Dumping
- T1685.006 Clear Linux or Mac System Logs
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1098 Account Manipulation

## Sources

- [Broadcom VMSA-2025-0004: VMware ESXi/Workstation/Fusion Multiple Vulnerabilities](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390)
- [NVD — CVE-2025-22225](https://nvd.nist.gov/vuln/detail/CVE-2025-22225)
- [NVD — CVE-2025-22224](https://nvd.nist.gov/vuln/detail/CVE-2025-22224)
- [NVD — CVE-2025-22226](https://nvd.nist.gov/vuln/detail/CVE-2025-22226)
- [CISA KEV — CVE-2025-22225 (Known Ransomware, Due: March 25, 2025)](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-22225)
- [VMSA-2025-0004 FAQ](https://brcm.tech/vmsa-2025-0004)
- [ESXi 8.0 U3d Release Notes](https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-80u3d-release-notes.html)
- [ESXi 7.0 U3s Release Notes](https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/7-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-70u3s-release-notes.html)
- [VCF Async Patching Guide (KB88287)](https://knowledge.broadcom.com/external/article?legacyId=88287)
- [MITRE ATT&CK — T1611: Escape to Host](https://attack.mitre.org/techniques/T1611/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0093
