ESXi 6.5 CVE and ESXi 6.7 CVE lists have a hard stop: both versions hit end of general support on October 15, 2022, and no CVE disclosed since gets evaluated or patched. ESXi 7.0 carries KEV-listed CVE-2024-37085 with Broadcom's own words: 'No Patch Planned.' Every CISA KEV-listed ESXi CVE, the ESXiArgs record on 6.x, and the 8.0 / 9.x decision.
Every KEV-listed ESXi CVE — and where a patch exists
| CVE | What it is | KEV added | Fixed in | Status on 6.5 / 6.7 / 7.0 |
|---|---|---|---|---|
| CVE-2025-22224 | VMCI TOCTOU race condition → out-of-bounds write; code execution on the host from inside a VM (CVSS 9.3, per VMSA-2025-0004 ) | Mar 4, 2025 | 7.0 U3s, 8.0 U2d, 8.0 U3d | 7.0 patched (still supported at the time); 6.x absent from the advisory matrix |
| CVE-2025-22225 | Arbitrary kernel write → sandbox escape (CVSS 8.2, VMSA-2025-0004) | Mar 4, 2025 | 7.0 U3s, 8.0 U2d, 8.0 U3d | Same as above |
| CVE-2025-22226 | HGFS out-of-bounds read → information disclosure from the VMX process (CVSS 7.1, VMSA-2025-0004) | Mar 4, 2025 | 7.0 U3s, 8.0 U2d, 8.0 U3d | Same as above |
| CVE-2024-37085 | Active Directory ESX Admins authentication bypass; ransomware-exploited (Akira, Black Basta) ( VMSA-2024-0013 ) |
Jul 30, 2024 | 8.0 U3 only | 7.0: No Patch Planned — Broadcom's words; 6.x not evaluated |
| CVE-2020-3992 | OpenSLP use-after-free → remote code execution via port 427 (CVSS 9.8, VMSA-2020-0023 ) | Nov 3, 2021 | 7.0.1, ESXi670-202010401-SG, ESXi650-202010401-SG | Patches exist for 6.5/6.7 — shipped in 2020, while both were supported |
| CVE-2019-5544 | OpenSLP heap overwrite → remote code execution via port 427 (CVSS 9.8, VMSA-2019-0022) | Nov 3, 2021 | ESXi670-201912001, ESXi650-201912001, ESXi600-201912001 | Patches exist for 6.0/6.5/6.7 — shipped in 2019, while supported |
What's covered
- The 7.0 problem: an exploited CVE with "No Patch Planned" in the vendor's own matrix
- Every KEV-listed ESXi CVE — and where a patch exists
- ESXiArgs: the proof that EOL ESXi gets exploited at scale
- Every ESXi version's dates
- The decision: 8.0, 9.x, or off the platform
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-esxi-cve-exposure
Top comments (0)