CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has verified that ransomware groups are currently exploiting CVE-2025-22225, a significant VMware ESXi sandbox escape vulnerability.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has verified that ransomware groups are currently exploiting CVE-2025-22225, a significant VMware ESXi sandbox escape vulnerability.
This vulnerability, addressed by Broadcom in March 2025, allows attackers to bypass virtual machine isolation, facilitating ransomware deployment across hypervisors.
CVE-2025-22225 is an arbitrary write vulnerability in VMware ESXi, with an Important rating and a CVSS score of 8.2. Exploitation allows malicious actors with VMX process privileges to initiate an arbitrary kernel write, leading to hypervisor control.
It was disclosed alongside two other zero-days, CVE-2025-22224 (CVSS 9.3, heap overflow) and CVE-2025-22226 (CVSS 7.1, information disclosure), all of which have been exploited since early 2025.
CVE ID CVSS Score Description Affected Products
CVE-2025-22224 9.3 Heap overflow in VMCI driver ESXi 7.0, 8.0; Workstation 17.0
CVE-2025-22225 is an arbitrary write vulnerability in VMware ESXi, with an Important rating and a CVSS score of 8.2.
CVE-2025-22225 8.2 Arbitrary kernel write via VMX ESXi 7.0, 8.0
CVE-2025-22226 7.1 HGFS memory leak ESXi, Workstation, Fusion
CISA added CVE-2025-22225 to its Known Exploited Vulnerabilities (KEV) catalog on March 4, 2025, requiring federal patches by March 25 under BOD 22-01.
Recent updates on February 3, 2026, have highlighted its use in ransomware campaigns, although details on specific groups have not been disclosed. Attackers combine this with other vulnerabilities for complete VM escape, targeting enterprise hypervisors managing sensitive data.
Ransomware actors often gain initial VM access through administrative privileges, disabling VMCI drivers, loading unsigned kernel drivers, and leaking VMX memory to bypass ASLR.
This behavior facilitates the deployment of backdoors such as VSOCKpuppet for sustained hypervisor control while avoiding network detection. Previous exploitation by Chinese-linked hackers began in February 2024 via compromised SonicWall VPNs, leading to data exfiltration and ransomware preparation.
Broadcom's VMSA-2025-0004 advisory confirmed active exploitation at the time of the patch release. Scans indicate over 41,500 exposed ESXi instances remain vulnerable, increasing the risk of ransomware attacks. A toolkit targeting 155 ESXi builds was reported by Huntress, with development traces dating over a year prior.
It is imperative to apply Broadcom patches immediately for ESXi 7.0/8.0 and related products. CISA advises following vendor mitigations, implementing BOD 22-01 for cloud environments, or discontinuing systems that cannot be patched. Enhancing defenses with EDR monitoring for VMX anomalies, restricting VM administrative privileges, and scanning for indicators of compromise such as unsigned drivers or VSOCK traffic is also recommended.
Given the widespread use of VMware ESXi in enterprises, it remains a primary target for ransomware attacks. Organizations should prioritize patching hypervisors amidst increasing state-sponsored and cybercrime threats. Unpatched systems risk comprehensive infrastructure encryption and data breaches.
Based on reporting by Cyber Security News.
