Category: ESXi
-
VMware ESXi and VMware Workstation security vulnerability (CVE-2025-22224)
CVE-2025-22224 is a critical vulnerability classified as a Time-of-Check Time-of-Use (TOCTOU) flaw affecting VMware ESXi and VMware Workstation. In essence, the issue arises from a race condition where the system checks a resource and then uses it without verifying that it hasn’t changed, which can lead to an out-of-bounds write. This behavior can allow a…
-
VMware ESXi Authentication Bypass Vulnerability (CVE-2024-37085)
CVE-2024-37085 is an authentication bypass vulnerability in VMware ESXi. It allows a malicious actor with sufficient Active Directory (AD) permissions to gain full administrative access to an ESXi host. This vulnerability occurs when an attacker re-creates or renames an AD group to match the default ESXi group name (“ESXi Admins”), enabling unauthorized access. The group…