Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
CISA KEV·Added 2025-03-04 — agencies required to remediate by 2025-03-25

CVE-2025-22224

CRITICAL

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges…

Published
Mar 4, 2025
Updated
Oct 30, 2025
Affected
0 pkgs
Patched
None yet
Exploits
None indexed

EPSS Exploitation Probability

via FIRST.org ↗
46.8%probability of exploitation in next 30 days
High Risk98th percentile-0.59%
42.9%49.9%56.9%63.9%48.2%46.8%Dec 25Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Description

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

Affected Products

5 products · 56 configurations
Application
cloud foundationvmware
all
OS
esxivmware
2 versions
7.08.0
Application
telco cloud infrastructurevmware
4 versions
2.22.52.73.0
Application
telco cloud platformvmware
7 versions
2.02.52.73.04.04.0.15.0
Application
workstationvmware
≥ 17.0 && < 17.6.3
range

Frequently Asked Questions

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
O3 Security · Impact-Aware SCA

Is CVE-2025-22224 in your stack?

O3 detects CVE-2025-22224 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.