All CVEs
Vulnerability intelligence

CVE-2025-22225

VMware ESXi Arbitrary Write Vulnerability

VMware ESXi

VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.

CVSS Score
Unrated
EPSS — Exploit Probability
1.0%
Riskier than 60% of all CVEs · checked 2026-09-04
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
Unconfirmed
Federal deadline 2025-03-25
CISA required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2025-03-25.

NVD entry CISA KEV

1 article across 1 outlet · first covered Feb 4, 2026 · latest Feb 4, 2026

Coverage timeline

Related CVEs — VMware