← Back to CVE List
CVE-2025-22226NVD
Vulnerability Summary
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
CVSS v3.1 Base Metrics — Score 7.1 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- Vmware Esxi
- Vmware Cloud Foundation
- Vmware Fusion >= 13.0.0 and < 13.6.3
- Vmware Telco Cloud Infrastructure
- Vmware Telco Cloud Platform
- Vmware Workstation >= 17.0 and < 17.6.3
- Vmware Fusion 13.6.3
- Vmware Workstation 17.6.3