VMware splats guest-to-hypervisor escape bugs already exploited in wild
ID: b27e0a7f-e63b-5db1-9ca3-814784be8b1f
STIX ID: report--b27e0a7f-e63b-5db1-9ca3-814784be8b1f
Feed Name: The Register (Security)
Broadcom released patches for three VMware hypervisor vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) that can be chained to escape a guest VM and fully compromise the hypervisor; the most severe is rated CVSS 9.3. Microsoft reported the bugs to Broadcom, VMware indicates in-the-wild exploitation has occurred, and administrators are urged to update and reboot affected ESXi, vSphere, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform systems promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
