{"cveID":"CVE-2025-22224","vendorProject":"VMware","product":"ESXi and Workstation","vulnerabilityName":"VMware ESXi and Workstation TOCTOU Race Condition Vulnerability","dateAdded":"2025-03-04","shortDescription":"VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-03-25","knownRansomwareCampaignUse":"Unknown","notes":"https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390 ; https://nvd.nist.gov/vuln/detail/CVE-2025-22224","cwes":["CWE-367"],"year":2025,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2025-22224","technique":"T1055","technique_name_at_mapping":"Process Injection","mapping_type":"exploitation_technique","capability_group":"oob","comments":"By exploiting the TOCTOU vulnerability in VMWare ESXi, Workstation, and Fusion, an attacker with local admin privileges can execute code in the VMX process on the host, in effect, functioning as an escape from the virtual machine to the host system.","references":["https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390"," https://westoahu.hawaii.edu/cyber/vulnerability-research/vulnerabilities-weekly-summaries/attacks-on-vmware-esxi/#:~:text=all%20impacted%20products.-","Exploitation","of%20VMs%20compromising%20the%20host."],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-22224","technique":"T1611","technique_name_at_mapping":"Escape to Host","mapping_type":"primary_impact","capability_group":"oob","comments":"By exploiting the TOCTOU vulnerability in VMWare ESXi, Workstation, and Fusion, an attacker with local admin privileges can execute code in the VMX process on the host, in effect, functioning as an escape from the virtual machine to the host system.","references":["https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390"," https://westoahu.hawaii.edu/cyber/vulnerability-research/vulnerabilities-weekly-summaries/attacks-on-vmware-esxi/#:~:text=all%20impacted%20products.-","Exploitation","of%20VMs%20compromising%20the%20host."],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1055","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Process Injection","name_at_mapping":"Process Injection","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":37,"has_detection_strategy":true},{"id":"T1611","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Escape to Host","name_at_mapping":"Escape to Host","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":2,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}