DEV Community

endoflife-ai
endoflife-ai

Posted on • Originally published at endoflife.ai

ESXi 6.5, 6.7 & 7.0 CVEs: What Is Unpatched — and What Will Never Be Patched

ESXi 6.5 CVE and ESXi 6.7 CVE lists have a hard stop: both versions hit end of general support on October 15, 2022, and no CVE disclosed since gets evaluated or patched. ESXi 7.0 carries KEV-listed CVE-2024-37085 with Broadcom's own words: 'No Patch Planned.' Every CISA KEV-listed ESXi CVE, the ESXiArgs record on 6.x, and the 8.0 / 9.x decision.

Every KEV-listed ESXi CVE — and where a patch exists

CVE What it is KEV added Fixed in Status on 6.5 / 6.7 / 7.0
CVE-2025-22224 VMCI TOCTOU race condition → out-of-bounds write; code execution on the host from inside a VM (CVSS 9.3, per VMSA-2025-0004 ) Mar 4, 2025 7.0 U3s, 8.0 U2d, 8.0 U3d 7.0 patched (still supported at the time); 6.x absent from the advisory matrix
CVE-2025-22225 Arbitrary kernel write → sandbox escape (CVSS 8.2, VMSA-2025-0004) Mar 4, 2025 7.0 U3s, 8.0 U2d, 8.0 U3d Same as above
CVE-2025-22226 HGFS out-of-bounds read → information disclosure from the VMX process (CVSS 7.1, VMSA-2025-0004) Mar 4, 2025 7.0 U3s, 8.0 U2d, 8.0 U3d Same as above
CVE-2024-37085 Active Directory ESX Admins authentication bypass; ransomware-exploited (Akira, Black Basta) ( VMSA-2024-0013 ) Jul 30, 2024 8.0 U3 only 7.0: No Patch Planned — Broadcom's words; 6.x not evaluated
CVE-2020-3992 OpenSLP use-after-free → remote code execution via port 427 (CVSS 9.8, VMSA-2020-0023 ) Nov 3, 2021 7.0.1, ESXi670-202010401-SG, ESXi650-202010401-SG Patches exist for 6.5/6.7 — shipped in 2020, while both were supported
CVE-2019-5544 OpenSLP heap overwrite → remote code execution via port 427 (CVSS 9.8, VMSA-2019-0022) Nov 3, 2021 ESXi670-201912001, ESXi650-201912001, ESXi600-201912001 Patches exist for 6.0/6.5/6.7 — shipped in 2019, while supported

What's covered

  • The 7.0 problem: an exploited CVE with "No Patch Planned" in the vendor's own matrix
  • Every KEV-listed ESXi CVE — and where a patch exists
  • ESXiArgs: the proof that EOL ESXi gets exploited at scale
  • Every ESXi version's dates
  • The decision: 8.0, 9.x, or off the platform

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-esxi-cve-exposure

Top comments (0)