Target Industry
Black Basta and Cactus ransomware groups, primarily targets the manufacturing, financial consulting, and real estate.
Overview
VMware has patched three critical vulnerabilities in its virtual machine products, which could allow threat actors to gain extensive access to sensitive environments. VMware has evidence that these vulnerabilities are already being actively exploited. Organisations using the affected products should investigate and secure their networks promptly.
Impact
These vulnerabilities, known as hyperjacking, or virtual machine (VM) escape, enable threat actors to control the hypervisor and access multiple VMs within a hosting environment.
The vulnerabilities affect VMware’s ESXi, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform product lines. They include a heap overflow, an arbitrary write vulnerability, and an information-disclosure vulnerability.
The affected versions of the products are:
- Telco Cloud Platform 5.0 (ESXi 8.0U3)
- Telco Cloud Platform 4.0.1 (ESXi 8.0U2b)
- Telco Cloud Platform 4.0 (ESXi 8.0U2b)
- Telco Cloud Platform 3.0 (ESXi 8.0b)
- Telco Cloud Platform 2.7 (ESXi 7.0U3g)
- Telco Cloud Platform 2.5 (ESXi 7.0U3f)
- Telco Cloud Platform 2.0 (ESXi 7.0U1a)
- VMware Cloud Foundation 4.5.x
- VMware ESXi 8.0: Versions ESXi80U3d-24585383 and ESXi80U2d-24585300
- VMware ESXi 7.0: Version ESXi70U3s-24585291
- VMware Fusion 13.x
- VMware Workstation 17.0: Versions 17.0.2 and 17.0.1
Exploitation
The VMware hyperjacking vulnerabilities are exploited through a series of steps that allow threat actors to gain control over the hypervisor from within a VM. Here’s a breakdown of how these vulnerabilities can be exploited:
- Initial Compromise: The threat actor first needs to gain administrative privileges within a VM. This could be achieved through various means, such as exploiting other vulnerabilities or using social engineering techniques.
- Heap Overflow (CVE-2025-22224, CVSS score 9.3): Once inside the VM, the threat actor can exploit a heap overflow vulnerability in the VM Communication Interface (VMCI). This allows the threat actor to execute arbitrary code as the VMX process running on the host.
- Arbitrary Write (CVE-2025-22225, CVSS score 7.1): The threat actor then uses an arbitrary write vulnerability to manipulate the memory of the VMX process. This step is crucial for escaping the VM and gaining control over the hypervisor.
- Information Disclosure (CVE-2025-22226, CVSS score 8.2): Finally, the threat actor exploits an information disclosure vulnerability to leak sensitive information from the VMX process, further solidifying their control over the hypervisor.
By chaining these vulnerabilities together, a threat actor can escape the isolated environment of a VM and gain control over the hypervisor, potentially compromising all VMs hosted on that hypervisor.
Containment, Mitigations & Remediations
To mitigate the VMware hyperjacking vulnerabilities (CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226), follow these steps:
- Ensure to apply the latest patches provided by VMware for the affected products, including ESXi, Workstation, Fusion, and Telco Cloud Platform.
- Keep hypervisors up-to-date with the latest security patches to prevent exploitation of known vulnerabilities.
- Implement Strong Access Controls:
- Use multi-factor authentication (MFA) for accessing hypervisor management interfaces.
- Apply the principle of least privilege, ensuring that only necessary permissions are granted to users.
- Separate the management network from the regular traffic network to reduce the risk of unauthorised access.
- Regularly monitor and audit hypervisor and VM activities to detect any unusual behaviour or potential breaches.
Threat Landscape
VMware has a substantial user base, with over 500,000 organisations worldwide utilising its virtualisation and cloud infrastructure solutions. These vulnerabilities pose a significant threat as it could compromise multiple customers’ networks hosted in these environments.
Threat Groups
The specific threat group behind this has not been publicly identified at the time of writing.
TTPs
- T1190: Exploit Public-Facing Application
- T1203: Exploitation for Client Execution
- T1068: Exploitation for Privilege Escalation
- T1070: Indicator Removal on Host
- T1021: Remote Services
- T1485: Data Destruction
Further Information













