Skip to main content

ESXi vulnerabilities

3 published alerts for VMware ESXi.

Actively exploited (KEV)Ransomware

CVE-2025-22225

VMware ESXi Arbitrary Write Vulnerability

VMware ESXi is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-22225). VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox. CISA remediation due date: 2025-03-25. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-37085

VMware ESXi Authentication Bypass Vulnerability

VMware ESXi is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-37085). VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD. CISA remediation due date: 2024-08-20. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-3992

VMware ESXi OpenSLP Use-After-Free Vulnerability

VMware ESXi is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-3992). VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.