Breaking
March 10, 2025

Broadcom releases fixes for multiple VMware security flaws | usagoldmines.com


  • Broadcom releases fix for three vulnerabilities being abused in the wild
  • The bugs were described as VM escape flaws
  • The company urged users to apply the fix as soon as possible

Broadcom has released a fix for three vulnerabilities, affecting a number of its VMware products, one of which is deemed critical, and is already being abused in the wild.

In a security advisory published, Broadcom said it released a patch that addresses VM escape vulnerabilities tracked as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226. A VM escape is a vulnerability that allows an attacker who has already compromised a virtual machine’s guest OS and gained privileged access to move into the hypervisor itself.

The bugs affect all supported versions of VMware ESX, VMware vSphere, VMware Cloud Foundation, and VMware Telco Cloud Platform. They were assigned severity scores 9.3, 8.2, and 7.1, respectively.

Targeting VMware

“Broadcom has information to suggest that exploitation of these issues has occurred “in the wild,” the company said in the advisory.

Since VMware solutions are often found in both enterprise and SMB environments, they are a popular target among cybercriminals looking to access sensitive company data. To tackle the constant threat, Broadcom continuously scans for vulnerabilities and patches them.

In mid-November 2024, for example, Broadcom warned of two flaws plaguing its VMware vCenter Server product, which were being exploited in the wild. Just as today, the company then urged users to apply the patch immediately, and warned there were no workarounds. The vulnerabilities could be used to cause quite the damage to compromised networks.

Earlier still, in March 2024, VMware patched a whole host of security vulnerabilities affecting a number of its key business products. The vulnerabilities affected ESXi, Workstation, and Fusion products, and are tracked as CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, and CVE-2024-22255. The first two are described as use-after-free flaws in the XHCI USB controller, affecting all three products. For Workstation and Fusion, they carry a severity score of 9.3, while for ESXi, it’s 8.4.

Via BleepingComputer

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Buying a PC game controller is all about options. Cut through the BS with this guide | usagoldmines...

Revealed: The new laptop battery level icons coming to Windows 11 | usagoldmines.com

PNY CS2150 SSD review: This is the PCIe 5.0 value buy to beat | usagoldmines.com

Why you should never, ever delete spam email | usagoldmines.com

Beware! Fake parking ticket SMS scams are on the rise | usagoldmines.com

This Ryzen 7 mini PC supports three 4K displays for just $299 | usagoldmines.com

Filmora 14 adds quality audio from Universal Music for Creators | usagoldmines.com

Acer’s 1440p OLED gaming monitor is 55% off — today only! | usagoldmines.com

Some older Chromecasts are suddenly ‘untrusted’, can’t cast anymore | usagoldmines.com

Best gaming monitors 2025: Level up your display | usagoldmines.com

Grab Lenovo’s RTX 4060 laptop for just $750 while you still can | usagoldmines.com

Lenovo put an AI chip in a monitor, for some reason | usagoldmines.com

Google Calendar gets dedicated side panel for Gemini AI assistant | usagoldmines.com

OnePlus Replacing Beloved Alert Slider With Customizable Button Tim | usagoldmines.com

My Favorite Amazon Deal of the Day: The Apple Watch Series 10 Daniel Oropeza | usagoldmines.com

Experts warn this critical PHP vulnerability could be set to become a global problem | usagoldmines...

X is down again – here's everything we know about Twitter's third outage of the day mark.wilson@futu...

Beware! Fake parking ticket SMS scams are on the rise | usagoldmines.com

Cybersecurity workers aren't massively happy with their employers - but they are being paid pretty w...

'We could not achieve that with puppetry or animatronics': Joe and Anthony Russo didn't want to buil...

Top Bluetooth chip security flaw could put a billion devices at risk worldwide | usagoldmines.com

RTX 5050 rumors detail full spec of desktop graphics card, suggesting Nvidia may use slower video RA...

OnePlus is ditching the Alert Slider for an iPhone-style customizable button - and I’ll be sad to se...

Software bug meant NHS information was potentially “vulnerable to hackers” | usagoldmines.com

Another top security camera maker is seeing devices hijacked into botnet | usagoldmines.com

Quordle hints and answers for Tuesday, March 11 (game #1142) | usagoldmines.com

NYT Strands hints and answers for Tuesday, March 11 (game #373) | usagoldmines.com

NYT Connections hints and answers for Tuesday, March 11 (game #639) | usagoldmines.com

Being ready when the cyber crisis happens | usagoldmines.com

The true threat of business downtime | usagoldmines.com

DOJ: Google must sell Chrome, Android could be next Ryan Whitwam | usagoldmines.com

Google Pixel 4a’s painful “update” was due to battery overheating risk Kevin Purdy | usagoldmines.co...

‘Expect pain at the cash register.’ PC insiders weigh in on tariffs | usagoldmines.com

How to use Windows 11 Pro to create an encrypted virtual drive | usagoldmines.com

Apple Watch Series 10 now on sale for lowest-ever price: $299 | usagoldmines.com

This Harman Kardon Bluetooth Speaker Is at Its Lowest Price Pradershika Sharma | usagoldmines.com

Apple Still Exploring Smart Glasses Similar to Meta's Ray-Bans Tim Hardwick | usagoldmines.com

Apple One's Best Plan Now Includes Two More Perks For Free Joe Rossignol | usagoldmines.com

iOS 18.3.2 Update Coming Soon for iPhones Joe Rossignol | usagoldmines.com

4 free temporary email services that stop spam dead | usagoldmines.com

My Favorite Unexpected Cleaning Tools for the Kitchen and Bathroom Lindsey Ellefson | usagoldmines.c...

The Out-of-Touch Adults' Guide to Kid Culture: International Women's Month Stephen Johnson | usagold...

Review Roundup: iPad Air With M3 Chip and New Magic Keyboard Joe Rossignol | usagoldmines.com

Worried about DeepSeek? Well, Google Gemini collects even more of your personal data chiara.castro@f...

Garmin owners were confused about 13.35 software update for Fenix 8, here's what actually happened s...

Nvidia's GeForce graphics driver woes continue for some users, despite 572.75 hotfix's overclock and...

Video Shows iPhone 17 Mockups Based on 'Internal Documents' Tim Hardwick | usagoldmines.com

Apple Pulls iPhone 16 Ad Showing Off 'More Personal Siri' Tim Hardwick | usagoldmines.com

Advantage, Alexa – Apple's smart home hub reportedly 'postponed' due to Siri slowdown alexblake.tech...

Major Oracle outage hits US Federal health record systems | usagoldmines.com

The new Ray-Ban Meta smart glasses design is an expensive disappointment hamish.hector@futurenet.com...

Q Acoustics wants to bring the bass to your post-Oscars movie catch-up | usagoldmines.com

The US government still wants Google to sell off Chrome | usagoldmines.com

The OLED iPad Pro is reportedly less popular than expected –and that could mean these changes to App...

Samsung’s new budget handsets are getting One UI 7 before the Galaxy S24 Ultra, and I’m as confused ...

Best TV antennas of 2025: Reviews and buying advice | usagoldmines.com

Best gaming laptops under $1,000: Expert picks that won’t break the bank | usagoldmines.com

Fastest VPN 2025: We identify the speediest performers | usagoldmines.com

Lenovo Yoga Slim 9i 14 review: Sleek and shiny, but with trade-offs | usagoldmines.com

Assassin's Creed Shadows PS5 Pro details have been revealed and the biggest difference appears to be...

Agentic AI has “profound” issues with security and privacy, Signal President says | usagoldmines.co...

Windows 11 users get ready for more ‘recommendations’ from Microsoft – but I’m relieved to say these...

UNA Watch is the sustainable wearable that wants to replace your Apple Watch stephen.warwick@futuren...

NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack | usagoldmi...

Hey AI DJ, put a record on: Spotify seems set to let you speak to its AI DJ | usagoldmines.com

Chromecast users are getting increasingly angry about a weird 'untrusted device' bug that blocks cas...

The next Xbox could simply be a PC in a 'TV-friendly shell' per latest rumor dash.wood@futurenet.com...

Death Stranding 2: On the Beach trailer confirms June release date and an even more harrowing post-a...

Better than the real thing? Spark 2 packs 39 amp sims into $300 Bluetooth speaker Nate Anderson | us...

Apple's Foldable iPad Pro Prototype Features Under-Display Face ID Tim Hardwick | usagoldmines.com

DeepSeek kicks off the next wave of the AI rush | usagoldmines.com

'We take the comprehensive view': Joe and Anthony Russo drop big hint over Marvel heroes from Disney...

Upgrading to a new PC? You’ll want to wipe your old laptop with this shredder | usagoldmines.com

CFOs: Are you ready to let go and trust AI? | usagoldmines.com

Ben Stiller and Eddy Cue Discuss Apple TV+ Series 'Severance' at SXSW Joe Rossignol | usagoldmines.c...

Best PC computer deals: Top picks from desktops to all-in-ones | usagoldmines.com

Study: Megalodon’s body shape was closer to a lemon shark Jennifer Ouellette | usagoldmines.com

Is the moon too far for your data? IBM's Red Hat is teaming up with Axiom Space to send a data cente...

Here's Why Apple is Unlikely to Release an M4 Ultra Chip for Macs Joe Rossignol | usagoldmines.com

New iOS 19 and visionOS 3 Tidbits Revealed Joe Rossignol | usagoldmines.com

The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades | u...

Well, that's unexpected: Samsung will team up with its fiercest Chinese rival to produce next gen NA...

New Apple Store Opens in UK, Another Coming Soon in Ohio Joe Rossignol | usagoldmines.com

AirPods 4 Hit $99.99 Low Price on Amazon, Plus Big Discounts on ANC Model and AirPods Max Mitchel Br...

I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-base...

Apple's Smart Home Hub Now 'Postponed' Due to Delayed Siri Features Joe Rossignol | usagoldmines.com

The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro ...

New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro M...

NYT Connections hints and answers for Monday, March 10 (game #638) | usagoldmines.com

Quordle hints and answers for Monday, March 10 (game #1141) | usagoldmines.com

NYT Strands hints and answers for Monday, March 10 (game #372) | usagoldmines.com

Chinese researchers are looking to create a revolutionary type of hard drive based on organic materi...

Andor is the best Star Wars TV show I’ve ever watched – here are 3 reasons why you should catch seas...

A breakthrough in computing: Cortical Labs' CL1 is the first living biocomputer and costs almost the...

Dynabook's newest laptop has a 4-year warranty, a swappable battery, a weight of under 1 kg, and eve...

Huh? The valuable role of interjections Bob Holmes, Knowable Magazine | usagoldmines.com

A perpetual license for this PDF editor is only $28 | usagoldmines.com

This $15 data visualization tool is off the chart | usagoldmines.com

Apple Introduced Its Most Controversial MacBook 10 Years Ago Today Hartley Charlton | usagoldmines.c...

ChatGPT remains the most popular AI tool in offices worldwide, survey finds, with India leading the ...

Leave a Reply