Vulnerability intelligence
CVE-2025-22225
VMware ESXi Arbitrary Write Vulnerability
VMware ESXi
VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.
CVSS Score
—
Unrated
EPSS — Exploit Probability
1.0%
Riskier than 60% of all CVEs · checked 2026-09-04
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
Unconfirmed
Federal deadline 2025-03-25
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2025-03-25.
1 article across 1 outlet · first covered Feb 4, 2026 · latest Feb 4, 2026
Coverage timeline
-
CVE-2025-22225 in VMware ESXi now used in active ransomware attackssecurityaffairs.com · Feb 4, 2026