Broadcom has released security updates to fix a high-severity vulnerability that allows authentication bypass in VMware Tools for Windows.
See also: Over 37,000 VMware ESXi servers vulnerable to attacks

VMware Tools is a collection of drivers and utilities designed to improve performance, graphics, and overall system integration for operating systems running in VMware virtual machines.
The CVE-2025-22230 results from an improper access control weakness and was reported by Sergey Bliznyuk of Positive Technologies, a Russian cybersecurity company that has been sanctioned and accused of distributing hacking tools.
Local attackers with low privileges can exploit this vulnerability in low-sophistication attacks that do not require user interaction, in order to gain elevated privileges on vulnerable virtual machines.
Earlier this month, Broadcom patched three zero-day vulnerabilities (CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226), which had been identified as exploitable in attacks and reported by the Microsoft Threat Intelligence Center.
See also: VMware warns of Blind SQL Injection flaw
The company explained at the time that attackers with privileged administrator or root access can combine these vulnerabilities to escape the virtual machine sandbox.

A few days after the updates were released, threat monitoring platform Shadowserver identified over 37,000 VMware ESXi instances exposed online that are vulnerable to authentication bypass attacks.
Ransomware groups and state-backed cybercriminals often target VMware vulnerabilities, as its products are widely used in business operations to store or transport sensitive corporate data.
For example, in November, Broadcom warned that attackers were exploiting two VMware vCenter Server vulnerabilities: one that allows elevation of privileges to root (CVE-2024-38813) and a critical remote code execution vulnerability (CVE-2024-38812), which was discovered during the Matrix Cup 2024 hacking in China.
In January 2024, Broadcom also announced that Chinese state hackers had exploited a critical vCenter Server zero-day vulnerability (CVE-2023-34048) from late 2021 to install the VirtualPita and VirtualPie on affected ESXi systems.
See also: New Akira Linux Ransomware Attacks VMware ESXi Servers
An authentication bypass refers to a weakness in a security system that allows an attacker to bypass the authentication process and gain access to resources or services that require authentication. This means that someone can gain access to an application, website, or system without being authorized or bypass the authentication process, such as through a security hole or error in the implementation of the authentication process.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
