VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
Details
CVSS Score
8.2
EPSS Score
ⓘ
1.00%
59.5th percentile
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Confidence
100%
Published
Mar 4, 2025
Last Modified
Aug 4, 2026
CISA KEV
Date Added
Mar 4, 2025
Patch Due
Mar 25, 2025
Used in ransomware campaigns
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.