VMware (Broadcom) ESXi
Our sources currently list 116 known vulnerabilities affecting VMware (Broadcom) ESXi. 16 are rated critical severity. 8 of 116 are actively exploited according to CISA, the most recent added 4 March 2025.
Last updated: 22 July 2026, 20:34 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2019-5544 | Critical (9.8) | Actively exploited · ransomware | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maxi… | |
| CVE-2020-3992 | Critical (9.8) | Actively exploited · ransomware | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor … | |
| CVE-2023-29552 | High (7.5) | Actively exploited | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to… | |
| CVE-2024-37085 | Medium (6.8) | Actively exploited · ransomware | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previ… | |
| CVE-2010-3904 | High (7.8) | Actively exploited | The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addres… | |
| CVE-2025-22226 | High (7.1) | Actively exploited | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a vir… | |
| CVE-2025-22224 | Critical (9.3) | Actively exploited | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges… | |
| CVE-2025-22225 | High (8.2) | Actively exploited · ransomware | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sa… | |
| CVE-2017-5753 | Medium (5.6) | Elevated likelihood (94%) | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side… | |
| CVE-2021-21974 | High (8.8) | Elevated likelihood (45%) | OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor resid… | |
| CVE-2010-0211 | Critical (9.8) | Elevated likelihood (29%) | The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denia… | |
| CVE-2016-5330 | High (7.8) | Elevated likelihood (18%) | Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMw… | |
| CVE-2009-2698 | High (7.8) | No exploitation reported | The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a d… | |
| CVE-2022-21125 | Medium (5.5) | No exploitation reported | Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| CVE-2017-16544 | High (8.8) | No exploitation reported | In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitiz… | |
| CVE-2022-21123 | Medium (5.5) | No exploitation reported | Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| CVE-2022-21166 | Medium (5.5) | No exploitation reported | Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local… | |
| CVE-2022-29901 | Medium (5.6) | No exploitation reported | Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker wi… | |
| CVE-2021-22045 | High (7.8) | No exploitation reported | VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerabilit… | |
| CVE-2014-8370 | Medium (6.4) | No exploitation reported | VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to gain host OS privilege… | |
| CVE-2012-3288 | Critical (9.3) | No exploitation reported | VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware ESXi 3.5 through 5.0, and VMwa… | |
| CVE-2014-4241 | Medium (4.3) | No exploitation reported | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related … | |
| CVE-2013-3658 | Critical (9.4) | No exploitation reported | Directory traversal vulnerability in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to delete arbitrary host OS files via unspecified vectors. | |
| CVE-2017-4933 | High (8.8) | No exploitation reported | VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session… | |
| CVE-2024-22252 | Critical (9.3) | No exploitation reported | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine … | |
| CVE-2012-2448 | High (7.5) | No exploitation reported | VMware ESXi 3.5 through 5.0 and ESX 3.5 through 4.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via NFS traffic. | |
| CVE-2012-1516 | Critical (9.9) | No exploitation reported | The VMX process in VMware ESXi 3.5 through 4.1 and ESX 3.5 through 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overw… | |
| CVE-2017-4941 | High (8.8) | No exploitation reported | VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an… | |
| CVE-2013-3657 | High (7.5) | No exploitation reported | Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors. | |
| CVE-2018-6972 | Medium (6.5) | No exploitation reported | VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi550-201806401-BG), Workstation (14.x before 14.1.2… | |
| CVE-2018-6965 | High (8.1) | No exploitation reported | VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translato… | |
| CVE-2010-4263 | High (7.9) | No exploitation reported | The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34, when Single Root I/O Virtualization … | |
| CVE-2013-1405 | Critical (10.0) | No exploitation reported | VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client… | |
| CVE-2014-1207 | Medium (4.3) | No exploitation reported | VMware ESXi 4.0 through 5.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (NULL pointer dereference) by intercepting and modifying Network File Copy (NFC)… | |
| CVE-2012-2449 | Critical (9.0) | No exploitation reported | VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly co… | |
| CVE-2012-2450 | Critical (9.0) | No exploitation reported | VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly reg… | |
| CVE-2012-1517 | Critical (9.0) | No exploitation reported | The VMX process in VMware ESXi 4.1 and ESX 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) … | |
| CVE-2012-5703 | Medium (5.0) | No exploitation reported | The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1) RetrieveProp or (2) RetrievePr… | |
| CVE-2021-22050 | High (7.5) | No exploitation reported | ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service con… | |
| CVE-2024-22255 | High (7.1) | No exploitation reported | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine m… | |
| CVE-2018-6966 | High (8.1) | No exploitation reported | VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translato… | |
| CVE-2018-6967 | High (8.1) | No exploitation reported | VMware ESXi (6.7 before ESXi670-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain an out-of-bounds read vulnerability in the shader translato… | |
| CVE-2019-5536 | Medium (6.5) | No exploitation reported | VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vuln… | |
| CVE-2020-3976 | Medium (5.3) | No exploitation reported | VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be … | |
| CVE-2016-5331 | Medium (6.1) | No exploitation reported | CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attack… | |
| CVE-2013-1659 | High (7.6) | No exploitation reported | VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Ne… | |
| CVE-2009-2416 | Medium (6.5) | No exploitation reported | Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (ap… | |
| CVE-2012-1518 | High (8.3) | No exploitation reported | VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect AC… | |
| CVE-2019-5528 | Medium (5.3) | No exploitation reported | VMware ESXi 6.5 suffers from partial denial of service vulnerability in hostd process. Patch ESXi650-201907201-UG for this issue is available. | |
| CVE-2019-5516 | Medium (6.8) | No exploitation reported | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before … |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
8 of these are being actively exploited right now.
Our Newcastle team can audit your VMware (Broadcom) estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
