NVD disclosure day

Published threat advisories for March 4, 2025

CVE advisoryKnown Exploit

CVE-2025-22225

VMware ESXi Arbitrary Write Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

VMware ESXi has a vulnerability that allows an attacker with internal privileges to write to the kernel, potentially escaping the sandbox. This impacts VMware ESXi systems, risking data and system control. The business risk is elevated due to observed exploitation.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-22224

VMware ESXi and Workstation Local Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in VMware ESXi and Workstation allows a malicious actor with local administrative privileges within a virtual machine to execute code on the host system. This could impact host systems and data, posing a business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-48248

NAKIVO Backup and Replication Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

NAKIVO Backup & Replication software contains a path traversal vulnerability that may allow unauthorized reading of files. This could expose sensitive information and credentials, posing a risk to enterprise systems and data integrity. Organizations using the affected product should address this issue to protect their

• CISA KEV