Current update: This March 2025 article is retained as historical context. Its original version incorrectly said patches were not yet available, but Broadcom’s initial advisory already included fixed versions. Use VMSA-2025-0004: Current Remediation and Fixed Versions for current, remediation-first guidance.

Broadcom released VMSA-2025-0004 on March 4, 2025. The advisory covers serious vulnerabilities in VMware ESXi, Workstation, and Fusion, plus products that consume ESXi such as VMware Cloud Foundation and VMware Telco Cloud Platform. Fixed versions were available in the advisory’s response matrix at publication.

What is VMSA-2025-0004?

VMSA-2025-0004 addresses three vulnerabilities with distinct effects. CVE-2025-22224 is a Time-of-Check Time-of-Use vulnerability leading to an out-of-bounds write. Rated Critical with a maximum CVSSv3 score of 9.3, it may allow a malicious actor with local administrative privileges inside a VM to execute code as that VM’s VMX process on the host. It should not be described by itself as complete host takeover; the sandbox escape described in the advisory is CVE-2025-22225.

The advisory also includes two other significant vulnerabilities:

  • CVE-2025-22225: An arbitrary write vulnerability that could allow an attacker to escape the VMX sandbox, rated as important with a CVSSv3 score of 8.2.
  • CVE-2025-22226: An information disclosure vulnerability that could leak sensitive memory from the VMX process, with a CVSSv3 score of 7.1.

Broadcom’s current advisory says it has information suggesting exploitation of all three vulnerabilities has occurred in the wild.

Which Products Are Affected?

These vulnerabilities impact a wide range of VMware products, including:

  • VMware ESXi: The hypervisor powering many data centers.
  • VMware Workstation: Desktop virtualization software for developers and IT professionals.
  • VMware Fusion: Virtualization software for macOS users.

Broadcom’s response matrix covers ESXi 8.0 and 7.0, Workstation 17.x, Fusion 13.x, VCF 5.x and 4.5.x, and the listed Telco Cloud product branches. Use the advisory rather than extrapolating its status to releases that are not present in the matrix.

Why This Matters

Virtualization is a cornerstone of modern IT, so vulnerabilities across the guest/host boundary require urgent treatment. Depending on the vulnerability and the attacker’s starting privileges, these issues could be used to:

  • Execute code in a VM’s VMX process through CVE-2025-22224.
  • Escape the VMX sandbox through CVE-2025-22225 after obtaining VMX-process privileges.
  • Disclose memory from the VMX process through CVE-2025-22226.
  • Support a broader attack chain against virtualized workloads and infrastructure.

With exploitation already happening, the risk is real and immediate. Organizations and individuals relying on these VMware products must act swiftly to protect their environments.

What Should You Do?

Fixed versions are available, and Broadcom lists no workarounds. The correct response is to update affected products rather than wait for a patch or treat compensating controls as remediation:

  1. Assess Your Environment Identify which versions of ESXi, Workstation, or Fusion you’re running. Compare them against the affected versions listed in the advisory (available at Broadcom’s support page). If your systems are impacted, they’re at risk.
  2. Plan and Apply the Supported Update Follow the fixed-version matrix and product-specific guidance in the current follow-up. For VCF-managed hosts, use the VCF async-patching workflow referenced by the advisory.
  3. Use Defense-in-Depth Controls Without Mistaking Them for a Fix The following controls can reduce exposure, but Broadcom does not list them as workarounds and they do not replace the fixed build:
  • Restricting VM Administrative Access: Limit who has admin privileges on VMs to reduce the attack surface.
  • Network Segmentation: Isolate critical VMs and hypervisors to contain potential breaches.
  • Enhanced Monitoring: Watch for suspicious activity on hosts and VMs, such as unexpected process execution or memory access attempts.

The Bigger Picture

This advisory underscores a harsh reality: even foundational technologies like VMware’s virtualization platforms are not immune to flaws. With exploitation reported and no workaround listed, the priority is prompt deployment of a fixed or later supported version through the appropriate product lifecycle workflow.

If you are running an affected product, review the advisory, confirm your exact build, and deploy the appropriate update. After remediation, review available telemetry for possible activity that occurred before the update.

Stay proactive, stay secure.

Fixed Versions Published by Broadcom

The response matrix below records the minimum fixes Broadcom published for the affected branches in March 2025. ESXi 7.0 and VCF 4.5.x have since reached End of General Support, so those rows are historical minimums rather than current supported targets. Check the live advisory and lifecycle matrix before acting, and use the follow-up article for current remediation guidance.

Response Matrix:

VMware ProductVersionRunning OnCVECVSSv3SeverityFixed VersionWorkaroundsAdditional Documentation
VMware ESXi8.0AnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.3, 8.2, 7.1CriticalESXi80U3d-24585383NoneFAQ
VMware ESXi8.0AnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.3, 8.2, 7.1CriticalESXi80U2d-24585300NoneFAQ
VMware ESXi7.0AnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.3, 8.2, 7.1CriticalESXi70U3s-24585291NoneFAQ
VMware Workstation17.xAnyCVE-2025-22224, CVE-2025-222269.3, 7.1Critical17.6.3NoneFAQ
VMware Fusion13.xAnyCVE-2025-222267.1Important13.6.3NoneFAQ
VMware Cloud Foundation5.xAnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.3, 8.2, 7.1CriticalAsync patch to ESXi80U3d-24585383NoneAsync Patching Guide: KB88287
VMware Cloud Foundation4.5.xAnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.3, 8.2, 7.1CriticalAsync patch to ESXi70U3s-24585291NoneAsync Patching Guide: KB88287
VMware Telco Cloud Platform5.x, 4.x, 3.x, 2.xAnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.3, 8.2, 7.1CriticalKB389385NoneFAQ
VMware Telco Cloud Infrastructure3.x, 2.xAnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.3, 8.2, 7.1CriticalKB389385NoneFAQ