AMD Ionic Cloud Driver Vulnerabilities Affecting VMware ESX (CVE-2025-62623, CVE-2025-62624, CVE-2025-62627) — Threadlinqs Intelligence
As of 2026-08-25, AMD Ionic Cloud Driver Vulnerabilities Affecting VMware ESX (CVE-2025-62623, CVE-2025-62624, CVE-2025-62627) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-2146 · Severity: HIGH · CVSS: 8.8 · Status: PATCHED · Category: VULNERABILITY
AMD and VMware disclosed three vulnerabilities in AMD's ionic cloud driver for VMware ESX hosts using AMD-Pensando DPU hardware, reported through the AMD Bug Bounty Program. CVE-2025-62623 and
AMD and VMware jointly disclosed three vulnerabilities in the AMD ionic cloud driver -- the kernel-mode component in VMware ESXi that services AMD-Pensando Distributed Services Card (DPU/SmartNIC) hardware -- affecting ESXi 8.x and 9.x hosts. All three were reported to AMD through its Bug Bounty Program by researcher Ori Nimron (@orinimron123). CVE IDs were reserved on 2025-10-16, well before the coordinated public disclosure on 2026-05-12, indicating a multi-month private remediation window between AMD, VMware/Broadcom, and the researcher. The vulnerabilities are documented in AMD Security Bulletin AMD-SB-2001, referenced from a VMware Security Blog post published the same day as initial disclosure.
CVE-2025-62623 (CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer) and CVE-2025-62624 (CWE-122, Heap-based Buffer Overflow) are both heap-based buffer overflows in the ionic driver. Both carry an identical CVSS 4.0 vector (AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, base score 8.8): exploitation requires local access and only low privileges -- consistent with an attacker who already has code execution inside a guest VM on the affected host -- with no user interaction, though attack complexity is high. Successful exploitation could let that attacker perform operations beyond the intended memory buffer boundaries, escalate privileges, and potentially execute arbitrary code on the ESXi host itself, breaking out of the guest VM's intended boundary through the DPU driver interface. Both vulnerability-impact and subsequent-system-impact metrics (VC/VI/VA and SC/SI/SA) are rated High, reflecting total confidentiality, integrity, and availability compromise of the host, not just the guest.
CVE-2025-62627 (CWE-822, Untrusted Pointer Dereference, CVSS 4.0 7.2, vector AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H) is an untrusted pointer dereference in the same driver: it dereferences a pointer that originates from, or is influenced by, an untrusted source without validating that the pointer references memory the caller is permitted to access. An attacker operating within an unprivileged guest VM issues crafted requests to the ionic driver interface to induce reads of arbitrary kernel addresses or addresses mapped to neighboring guests. This directly undermines the tenant-isolation guarantee that multi-tenant virtualization depends on: a low-privileged tenant VM could read hypervisor kernel memory or memory contents belonging to a separate, higher-value tenant's VM on the same physical host. The vector's VA:H/SA:H components also indicate a meaningful availability impact (e.g., driver/host crash from an invalid dereference), not just confidentiality loss.
None of the three CVEs appear in the CISA Known Exploited Vulnerabilities catalog as of 2026-08-25, and no public proof-of-concept or exploit code has been identified; CISA's SSVC assessment (ADP v2.0.3, recorded 2026-05-13) rates CVE-2025-62627's exploitation status as 'none', the attack as not automatable, and technical impact as 'partial'; the CVE carries an EPSS score of 0.00097 (0.797th percentile) -- a very low probability of near-term exploitation. CVE-2025-62623 independently shows an EPSS of roughly 0.02%, consistent with the same assessment. The vulnerabilities surfaced through responsible disclosure via AMD's bug bounty program rather than in-the-wild observation. On 2026-05-14, Red Hat Product Security separately assessed the ionic-driver CVEs and determined they do not affect any currently supported Red Hat product, since the vulnerable component is specific to VMware ESXi's driver integration rather than the upstream/mainline Linux kernel.
The 'ionic' driver name traces to AMD-Pensando's open-source out-of-tree driver family published at github.com/pensando/dsc-drivers, which packages three related kernel modules -- ionic/ionic_mnic (the network interface driver, with a separate PCI-bus build for standard hosts and a plat
Weaknesses (CWE)
CWE-119, CWE-122, CWE-822
Target sectors: technology, cloudhosting
Target regions: Global
Timeline
- MITRE reserves CVE-2025-62623, CVE-2025-62624, and CVE-2025-62627 for AMD following the researcher's report through the AMD Bug Bounty Program, beginning a private coordinated-disclosure window of roughly seven months.
- AMD publishes Security Bulletin AMD-SB-2001 and VMware simultaneously publishes a security blog post disclosing the three ionic cloud driver vulnerabilities for ESX hosts with AMD-Pensando DPU hardware.
- NVD publishes CVE-2025-62623, CVE-2025-62624, and CVE-2025-62627 with CVSS v4.0 base scores of 8.8, 8.8, and 7.2 respectively; CISA's SSVC assessment (ADP v2.0.3) is recorded the same day, rating CVE-2025-62627's exploitation status as 'none', the attack as not automatable, and technical impact as 'partial'.
- NVD/CVE-record updates finalize for all three CVEs, formally closing the initial publication cycle.
- Red Hat Product Security assesses the ionic-driver CVEs and determines they do not affect any currently supported Red Hat product, since the vulnerable component is VMware ESXi's driver integration rather than upstream Linux.
- SentinelOne publishes a vulnerability database entry analyzing CVE-2025-62627's untrusted pointer dereference and its impact on tenant isolation between co-located guest VMs.
- AMD updates Security Bulletin AMD-SB-2001 with revised guidance after initial publication.
- NVD last-modifies all three CVE records; entries remain marked 'awaiting analysis' pending a full CNA/NIST CVSS assessment.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2025-62623, CVE-2025-62624, CVE-2025-62627, T1199, T1611, T1082, T1005, T1499.004, T1588.006, T1583.003, T1580, T1592.004