VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
Published: 2025-03-04
Broadcom published an advisory for three flaws in several VMware products that were exploited in the wild as zero-days. Organizations are advised to apply the available patches.
https://www.cisa.gov/news-events/ics-advisories/icsa-25-077-02
https://cloud.google.com/support/bulletins/index#gcp-2025-011
https://www.databreachtoday.com/broadcom-patches-actively-exploited-zero-days-in-vmware-esxi-a-27647
https://www.theregister.com/2025/03/04/vmware_plugs_three_hypervisorhijack_holes/
https://www.securityweek.com/broadcom-patches-3-vmware-zero-days-exploited-in-the-wild/
https://www.infosecurity-magazine.com/news/vmware-patch-exploited-zero-day/
https://www.darkreading.com/vulnerabilities-threats/vmware-zero-day-bugs-sandbox-escape
https://therecord.media/vmware-exploited-vulnerabilities-esxi-workstation-fusion
https://thehackernews.com/2025/03/vmware-security-flaws-exploited-in.html