Broadcom fixes three VMware zero-days exploited in attacks
ID: 3216e107-03b2-562c-a354-3a7a9da36939
STIX ID: report--3216e107-03b2-562c-a354-3a7a9da36939
Feed Name: Bleeping Computer
Threat Score
**Executive Summary:** Broadcom and Microsoft disclosed three critical VMware zero-day vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) that enable a privileged user inside a guest VM to perform heap overflow, arbitrary write, or information disclosure against the VMX process, allowing sandbox escape to the hypervisor; Broadcom indicates exploitation has occurred in the wild and the flaws impact multiple VMware ESX products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
