Opens in a new tab
vmblog logo 2024 wht (updated)

Broadcom Fixes Three Exploited VMware Zero-Days

Share: 

David Marshall | Published: March 4, 2025

Broadcom has released a security alert to warn VMware customers about three zero-days that have been exploited in the wild. The vulnerabilities (CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226) impact VMware ESX products, including VMware ESXi, vSphere, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform.

https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2025-0004

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390

CVE-2025-22224 has been described as a critical VMCI heap overflow vulnerability affecting VMware ESXi and Workstation that allows an attacker with local admin privileges on a virtual machine (VM) to “execute code as the virtual machine’s VMX process running on the host”.

CVE-2025-22225 affects VMware ESXi, is a high-severity arbitrary file write issue that allows an attacker with privileges within the VMX process to “trigger an arbitrary kernel write leading to an escape of the sandbox”.

CVE-2025-22226 affects VMware ESXi, Workstation and Fusion. It’s a high-severity information disclosure flaw caused by an out-of-bounds read bug in the HGFS component, which allows an attacker who has administrative privileges to a VM to leak memory from the VMX process. 

Recently, ?Broadcom warned that attackers were actively exploiting two VMware vCenter Server vulnerabilities that were patched in September. One allows privilege escalation to root (CVE-2024-38813) while the other is a critical remote code execution flaw (CVE-2024-38812) reported during China’s 2024 Matrix Cup hacking contest. In January 20204, Broadcom revealed that Chinese state hackers had exploited a critical vCenter Server vulnerability (CVE-2023-34048) as a zero-day since at least late 2021 to deploy VirtualPita and VirtualPie backdoors on vulnerable ESXi hosts.

Here’s what a couple of cybersecurity experts are saying about this news:

Patrick Tiquet, Vice President, Security & Architecture at Keeper Security, a Chicago-based provider of zero-trust and zero-knowledge cybersecurity software: 

These VMware flaws are a serious risk because they allow attackers to break out of a compromised Virtual Machine (VM) and take control of the underlying host system. The most critical vulnerability, CVE-2025-22224, lets attackers who already have admin access inside a VM execute code on the host, potentially giving them control over all the other VMs running on the same server. The danger here is that once attackers gain access at this level, they can spread across the entire system, steal data and install backdoors to maintain access. 

With confirmed exploitation in the wild, organizations must take immediate action. We’ve seen both cybercriminals and state-sponsored groups exploit VMware vulnerabilities in the past to establish long-term persistence. Businesses should prioritize patching, enforce strict access controls and implement strong authentication for administrators. Securing virtualized environments requires a proactive approach – waiting until an attack is detected is simply too late.

Jason Soroko, Senior Fellow at Sectigo, a Scottsdale, Arizona-based provider of comprehensive certificate lifecycle management (CLM):

VMware’s zero-day flaws pose a major risk. Attackers with administrative access can break out of guest OS sandboxes and seize hypervisor control. The critical CVE-2025-22224 enables a heap overflow to execute code as the host’s VMX process, while CVE-2025-22225 and CVE-2025-22226, both high-severity, offer similar escalation paths.  Recent exploits targeting vCenter Server (CVE-2024-38813 and CVE-2024-38812) and past state-sponsored attacks (CVE-2023-34048) reveal a consistent pattern of deep system penetration via VMware flaws.

Although the three vulnerabilities share the goal of escaping the virtual machine sandbox to compromise the hypervisor, they differ technically. Their varied profiles give attackers multiple options.  One flaw can be exploited independently, or they can be chained to build a more robust attack path, increasing the chance of a successful breach.

The likely attackers are sophisticated adversaries, often state-sponsored or APT groups, with the resources to breach initial defenses. Their end goals include establishing deep, persistent access to virtualized infrastructures, bypassing security boundaries, moving laterally, exfiltrating sensitive data, deploying additional malware, and disrupting services.

##