logo

Broadcom discloses three VMware vulnerabilities: VMSA-2025-0004

ID: 77bc21f1-e22f-5bf6-9cd6-72c6e0702472

STIX ID: report--77bc21f1-e22f-5bf6-9cd6-72c6e0702472

Feed Name: ThreatLocker Blog

Threat Score
85/100

Date Published: 2025-03-12

Date Updated: 2026-05-01

...
...

Broadcom disclosed three VMware vulnerabilities (CVEs 2025-22224/22225/22226) impacting ESXi, Workstation, Fusion and related products, including a CVSS 9.3 heap overflow that can enable remote code execution and an issue allowing kernel write/host escape; Microsoft reported active exploitation. ThreatLocker recommends updating VMware Workstation to 17.6.3 and offers application control and Detect (EDR) community policies to block, ringfence, or detect vulnerable versions and suspicious vmware-vmx.exe behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.