Vmware
Vmware Esxi: vulnerabilidades y CVE
Vmware Esxi tiene 153 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 11 son críticas y 8 figuran en el catálogo de explotación activa de CISA.
CVE153
Últimos 12 meses7
Críticas11
Explotadas activamente8
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-22225 | Alta (8.2) | 1.0% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. |
| CVE-2025-22226 | Media (6) | 1.8% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit… |
| CVE-2025-22224 | Alta (8.2) | 1.6% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this… |
| CVE-2024-37085 | Alta (7.2) | 27% | ⚠ Explotación activa | 25 jun 2024 | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user… |
| CVE-2023-29552 | Alta (7.5) | 64% | ⚠ Explotación activa | 25 abr 2023 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack… |
| CVE-2010-3904 | Alta (7.8) | 14% | ⚠ Explotación activa | 6 dic 2010 | The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which… |
| CVE-2020-3992 | Crítica (9.8) | 83% | ⚠ Explotación activa | 20 oct 2020 | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who… |
| CVE-2019-5544 | Crítica (9.8) | 97% | ⚠ Explotación activa | 6 dic 2019 | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-62627 | Alta (7.2) | 0.10% | — | 13 may 2026 | An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of… |
| CVE-2025-62624 | Alta (8.8) | 0.11% | — | 13 may 2026 | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. |
| CVE-2025-62623 | Alta (8.8) | 0.10% | — | 13 may 2026 | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. |
| CVE-2026-20879 | Alta (8.3) | 0.12% | — | 12 may 2026 | Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged… |
| CVE-2026-20794 | Crítica (9.3) | 0.13% | — | 12 may 2026 | Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged… |
| CVE-2026-20751 | Alta (8.3) | 0.12% | — | 12 may 2026 | Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user… |
| CVE-2025-25058 | Baja (2) | 0.11% | — | 10 feb 2026 | Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure.… |
| CVE-2025-41239 | Alta (7.1) | 2.9% | — | 15 jul 2025 | VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a… |
| CVE-2025-41238 | Crítica (9.3) | 0.45% | — | 15 jul 2025 | VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on… |
| CVE-2025-41237 | Crítica (9.3) | 0.45% | — | 15 jul 2025 | VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a… |
| CVE-2025-41236 | Crítica (9.3) | 2.5% | — | 15 jul 2025 | VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual… |
| CVE-2025-41228 | Media (4.3) | 0.89% | — | 20 may 2025 | VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL… |
| CVE-2025-41227 | Media (5.5) | 0.16% | — | 20 may 2025 | VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit… |
| CVE-2025-41226 | Media (6.8) | 0.24% | — | 20 may 2025 | VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or… |
| CVE-2025-22226 | Media (6) | 1.8% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit… |
| CVE-2025-22225 | Alta (8.2) | 1.0% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. |
| CVE-2025-22224 | Alta (8.2) | 1.6% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this… |
| CVE-2024-37086 | Media (6.8) | 0.19% | — | 25 jun 2024 | VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a… |
| CVE-2024-37085 | Alta (7.2) | 27% | ⚠ Explotación activa | 25 jun 2024 | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user… |
| CVE-2024-22273 | Alta (7.8) | 0.17% | — | 21 may 2024 | The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to… |
| CVE-2024-22255 | Alta (7.1) | 2.3% | — | 5 mar 2024 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to… |
| CVE-2024-22254 | Alta (8.2) | 0.50% | — | 5 mar 2024 | VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox. |
| CVE-2024-22253 | Media (6.7) | 0.65% | — | 5 mar 2024 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code… |
| CVE-2024-22252 | Media (6.7) | 3.5% | — | 5 mar 2024 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code… |
| CVE-2023-29552 | Alta (7.5) | 64% | ⚠ Explotación activa | 25 abr 2023 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack… |
| CVE-2022-31705 | Alta (8.2) | 1.1% | — | 14 dic 2022 | VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue… |
| CVE-2022-31699 | Baja (3.3) | 0.21% | — | 13 dic 2022 | VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure. |
| CVE-2022-31696 | Alta (8.8) | 0.32% | — | 13 dic 2022 | VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the… |
| CVE-2022-31681 | Media (6.5) | 0.21% | — | 7 oct 2022 | VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host. |
| CVE-2022-23825 | Media (6.5) | 0.78% | — | 14 jul 2022 | Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. |