CVE-2025-22225
KEV · ransomware High · CVSS 8.2- CVSS
- 8.2
- nvd
- EPSS
- —
- KEV
- Listed
- ransomware
- Class
- kernel local
- CWE-787, CWE-123
Description
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
References
Status: profiled · ingested 2026-08-04T06:00:54.000Z