CISA Confirms VMware ESXi 0-Day Vulnerability Exploited in Ransomware Operations
Cybersecurity The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting VMware ESXi to its Known Exploited Vulnerabilities (KEV) catalog. Identified as CVE-2025-22225, this zero-day vulnerability enables attackers to bypass security sandboxes and is actively being used…

Cybersecurity
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting VMware ESXi to its Known Exploited Vulnerabilities (KEV) catalog.
Identified as CVE-2025-22225, this zero-day vulnerability enables attackers to bypass security sandboxes and is actively being used in ransomware operations.
Technical Analysis of CVE-2025-22225
This vulnerability is classified as an arbitrary write memory management vulnerability (CWE-123). It affects the VMware ESXi hypervisor, a platform commonly utilized by enterprises for managing virtual machines.
The flaw is located within the VMX process, which handles the virtual machine’s execution environment.
| CVE ID | CVE-2025-22225 |
|---|---|
| Vendor/Product | VMware ESXi |
| Vulnerability Type | Arbitrary Write (Sandbox Escape) |
| CWE | CWE-123 (Write-what-where Condition) |
Successful exploitation requires an attacker to have existing privileges within the VMX process. Once achieved, the attacker can initiate an arbitrary kernel write.
This vulnerability is classified as an arbitrary write memory management vulnerability (CWE-123).
This allows the attacker to escape the virtual machine’s isolation, known as a sandbox escape, and gain unauthorized access to the host system.
Escaping the sandbox allows a threat actor to move from a contained environment to the central management layer, potentially controlling all virtual machines on the affected hypervisor.
CISA's inclusion of this CVE in the KEV catalog confirms active exploitation of this flaw in ransomware campaigns.
ESXi servers are targeted by ransomware groups because compromising a single hypervisor enables the encryption of multiple servers and critical workloads, maximizing disruption.
While no specific threat actor attribution was provided in the initial advisory, the complexity of the sandbox escape indicates the involvement of sophisticated operators.
In response, CISA has issued a binding operational directive requiring Federal Civilian Executive Branch (FCEB) agencies to identify and patch vulnerable VMware ESXi instances by March 25, 2025.
Private organizations are strongly advised to prioritize this patch, as ransomware groups often accelerate attacks once a vulnerability is publicly documented.
Administrators should apply vendor mitigations immediately or discontinue product use if a fix is not available.




