Aggregator
CVE-2024-9347 | Ultimate Toolkit Plugin up to 3.0.9 on WordPress cross site scripting
CVE-2024-9940 | Calculated Fields Form Plugin up to 5.2.45 on WordPress cross site scripting
CVE-2024-9240 | ReDi Restaurant Reservation Plugin up to 24.0902 on WordPress cross site scripting
CVE-2025-22224, CVE-2025-22225, CVE-2025-22226: Zero-Day Vulnerabilities in VMware ESXi, Workstation and Fusion Exploited
Broadcom published an advisory for three flaws in several VMware products that were exploited in the wild as zero-days. Organizations are advised to apply the available patches.
Update March 4: The Solutions section has been updated to note that VMware ESXi 6.7 is also affected and a fixed version is available.
BackgroundOn March 4, Broadcom published an advisory (VMSA-2025-0004) for three zero-day vulnerabilities across multiple VMware products:
CVEDescriptionCVSSv3CVE-2025-22224VMware ESXi and Workstation Heap-Overflow Vulnerability9.3CVE-2025-22225VMware ESXi Arbitrary Write Vulnerability8.2CVE-2025-22226VMware ESXi, Workstation and Fusion Information Disclosure Vulnerability7.1In addition to its advisory, Broadcom published a frequently asked questions (FAQ) document for these vulnerabilities: VMSA-2025-0004: Questions & Answers.
AnalysisCVE-2025-22224 is a TOCTOU (Time-of-Check Time-of-Use) vulnerability in VMWare ESXi and Workstation. A local, authenticated attacker with admin privileges could exploit this vulnerability to gain code execution on the virtual-machine executable (VMX) process.
CVE-2025-22225 is an arbitrary write vulnerability in VMware ESXi. A local, authenticated attacker with requisite privileges could exploit this vulnerability through the VMX process to escape the sandbox.
CVE-2025-22226 is an information-disclosure vulnerability in VMware ESXi, Workstation and Fusion. An authenticated, local attacker with admin privileges could exploit this vulnerability to cause the VMX process to leak contents from memory.
Exploited in the wild as zero-days
According to Broadcom, these vulnerabilities were discovered and disclosed by researchers at the Microsoft Threat Intelligence Center (MSTIC) and observed being exploited in the wild. No specific details about in-the-wild exploitation were shared.
Proof of conceptAt the time this blog post was published, there were no proofs-of-concept (PoCs) available for any of these three vulnerabilities.
SolutionVMware has released fixed versions for affected VMware products:
Affected ProductsCVEsFixed VersionsVMware ESXi 8.0CVE-2025-22224,CVE-2025-22225,
CVE-2025-22226ESXi80U3d-24585383,
ESXi80U2d-24585300VMware ESXi 7.0CVE-2025-22224,
CVE-2025-22225,
CVE-2025-22226ESXi70U3s-24585291VMware ESXi 6.7CVE-2025-22224,
CVE-2025-22225,
CVE-2025-22226ESXi670-202503001VMware Workstation 17.xCVE-2025-22224,
CVE-2025-2222617.6.3VMware Fusion 13.xCVE-2025-2222613.6.3
Additionally, VMware Cloud Foundation and VMware Telco Cloud Platform and Telco Cloud Infrastructure are affected. An asynchronous patch is available for VMware Cloud Foundation, while Telco Cloud Platform customers should update to a fixed ESXi version. For more information, please refer to Broadcom’s advisory.
Thanks to Tom Sellers for identifying that VMware ESXi 6.7 is also affected and a fixed version is available.
A list of Tenable plugins for these vulnerabilities can be found on the individual CVE pages for CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 as they’re released. These links will display all available plugins for these vulnerabilities, including upcoming plugins in our Plugins Pipeline.
Get more informationChange LogUpdate March 4: The Solutions section has been updated to note that VMware ESXi 6.7 is also affected and a fixed version is available.
Join Tenable's Security Response Team on the Tenable Community.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
New Eleven11bot botnet infects 86,000 devices for DDoS attacks
CVE-2025-20002 | GMOD Apollo up to 2.7.x information exposure (icsa-25-063-07)
CVE-2025-24924 | GMOD Apollo up to 2.7.x missing authentication (icsa-25-063-07)
CVE-2025-23410 | GMOD Apollo up to 2.7.x Web Interface path traversal (icsa-25-063-07)
CVE-2025-21092 | GMOD Apollo up to 2.7.x privileges assignment (icsa-25-063-07)
Qilin
CVE-2025-1316 | Edimax IC-7100 IP Camera Requests os command injection (icsa-25-063-08)
CVE-2025-1259 | Arista EOS up to 4.33.1 OpenConfig access control
CVE-2025-1260 | Arista EOS up to 4.33.1 OpenConfig access control
RansomHub
CVE-2025-26202 | DZS Router Web Interface Passphrase cross site scripting
CVE-2025-1969 | Amazon AWS Temporary Elevated Access Management for IAM Identity Center origin validation (GHSA-x9xv-r58p-qh86)
DEF CON 32 – War Stories – Xiaomi The Money: Our Toronto Pwn2Own Exploit & BTS Story
Authors/Presenters: Ken Gannon, Ilyes Beghdadi
Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – War Stories – Xiaomi The Money: Our Toronto Pwn2Own Exploit & BTS Story appeared first on Security Boulevard.