Database/Kernel, userspace & hypervisor
VMware ESXi / Workstation: TOCTOU race leading to an out-of-bounds write in VMX - full VM escape to host code execution
CVE-2025-22224Kernel, userspace & hypervisorKnown exploitedcurated
Impact
TOCTOU race leading to an out-of-bounds write in VMX - full VM escape to host code execution; exploited in the wild as a zero-day [KEV]
Who can reach it
Tenant VM guest (local admin inside the VM)
What to do
ESXi patch + host reboot with vMotion evacuation. GPU-passthrough VMs cannot vMotion, so this is a tenant-visible drain. Top-priority escape of the 2025 set
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.