You are here
Home > Novosti > Preuzmite zakrpe za VMware ranjivosti

Preuzmite zakrpe za VMware ranjivosti

Broadcom je upozorio korisnike na tri VMware ranjivosti koje se koriste u napadima.

VMware ranjivosti često se koriste za ransomware napade jer je popularan odabir za virtualizaciju i koriste ga mnogi poslovni korisnici (npr. za pohranu ili prijenos osjetljivih poslovnih podataka).

Pogođeni proizvodi: VMware ESXi, VMware Workstation Pro / Player (radna stanica), VMware Fusion, VMware Cloud Foundation, VMware Telco Cloud platforma.

Ranjivosti:

CVE-2025-22224 – CVSS 9,3
CVE-2025-22225 – CVSS 8,2
CVE-2025-22226 – CVSS 7,1

Iskorištavanjem ovih ranjivosti napadači mogu pobjeći iz virtualnog stroja (sandboxa).

Sve o ranjivim verzijama i dostupnim zakrpama pronađite na stranici: Support Content Notification – Support Portal – Broadcom support portal.

Tablica ranjivosti:

VMware ProductVersionRunning OnCVECVSSv3SeverityFixed VersionWorkaroundsAdditional Documentation
VMware ESXi8.0AnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.38.27.1CriticalESXi80U3d-24585383NoneFAQ
VMware ESXi8.0AnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.38.27.1CriticalESXi80U2d-24585300NoneFAQ
VMware ESXi7.0 AnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.38.27.1CriticalESXi70U3s-24585291NoneFAQ
VMware Workstation17.xAnyCVE-2025-22224,  CVE-2025-222269.37.1Critical17.6.3NoneFAQ
VMware Fusion13.xAnyCVE-2025-22226 7.1Important13.6.3NoneFAQ
VMware Cloud Foundation 5.xAnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.38.27.1CriticalAsync patch to ESXi80U3d-24585383NoneAsync Patching Guide: KB88287
VMware Cloud Foundation 4.5.xAnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.38.27.1CriticalAsync patch to ESXi70U3s-24585291NoneAsync Patching Guide: KB88287
VMware Telco Cloud Platform5.x, 4.x, 3.x, 2.xAnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.38.27.1CriticalKB389385NoneFAQ
VMware Telco Cloud Infrastructure3.x, 2.x AnyCVE-2025-22224, CVE-2025-22225, CVE-2025-222269.38.27.1CriticalKB389385NoneFAQ
Top
More in Novosti
Newsletter Nacionalnog CERT-a CERT-info

Pročitajte novi broj Newslettera Nacionalnog CERT-a. Tema mjeseca drugog newslettera je Dan sigurnijeg interneta u sklopu koje vam donosimo pregled...

Close