logo

VMware splats guest-to-hypervisor escape bugs already exploited in wild

ID: b27e0a7f-e63b-5db1-9ca3-814784be8b1f

STIX ID: report--b27e0a7f-e63b-5db1-9ca3-814784be8b1f

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-03-04

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Broadcom released patches for three VMware hypervisor vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) that can be chained to escape a guest VM and fully compromise the hypervisor; the most severe is rated CVSS 9.3. Microsoft reported the bugs to Broadcom, VMware indicates in-the-wild exploitation has occurred, and administrators are urged to update and reboot affected ESXi, vSphere, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform systems promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.