
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability (CVE-2025-22226) discovered on March 4, 2025. The vulnerability is due to an out-of-bounds read in HGFS (Host Guest File System) and affects multiple VMware products including ESXi, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform (VMware Advisory, NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 7.1 (High) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N. The flaw is classified as CWE-125 (Out-of-bounds Read) and requires local access to exploit. The vulnerability specifically affects the HGFS component and can be triggered by an attacker with administrative privileges to a virtual machine (VMware Advisory, Rapid7).
If successfully exploited, this vulnerability allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process. This could potentially expose sensitive information from the hypervisor (VMware Advisory, SOCRadar).
Broadcom has released patches to address this vulnerability. Organizations should upgrade to VMware Fusion version 13.6.3, VMware Workstation version 17.6.3, and apply the corresponding patches for ESXi and other affected products. There are no viable workarounds, and disabling VMware Tools does not eliminate the risk as attackers with privileged access can re-enable it (VMware Advisory).
The security community has expressed significant concern about this vulnerability, particularly due to its active exploitation in the wild. The Microsoft Threat Intelligence Center initially discovered and reported the vulnerability to Broadcom, highlighting the collaborative nature of security research in addressing critical vulnerabilities (SOCRadar).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”