target entity

ESXi

3 source-linked records in the current knowledge graph.

high

CVE-2025-22225: VMware ESXi Arbitrary Write Vulnerability

VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-22225EPSS 1.0%ESXiVMware
CISA KEV ↗ · unattributed attribution
high

CVE-2024-37085: VMware ESXi Authentication Bypass Vulnerability

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-37085EPSS 26.8%ESXiVMware
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3992: VMware ESXi OpenSLP Use-After-Free Vulnerability

VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution. Required action: Apply updates per vendor instructions.

CVE-2020-3992EPSS 83.0%ESXiVMware
CISA KEV ↗ · unattributed attribution