logo

Zero-Days Put Tens of 1,000s of Orgs at Risk for VM Escape Attacks

ID: 6cf605a7-6aca-51e2-bc5b-e530c2620e04

STIX ID: report--6cf605a7-6aca-51e2-bc5b-e530c2620e04

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-03-07

Date Updated: 2026-04-21

Author: Rob Wright

...
...

Three high-severity zero-day vulnerabilities in VMware ESXi/Workstation/Fusion (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) could be chained to allow a VM escape and compromise hosts or co-tenant VMs; Shadowserver observed ~41,000+ vulnerable ESXi instances, exploitation requires guest admin privileges and chaining of all three flaws, patches are available and no public exploit code has been reported yet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.