{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"VMware Cloud Foundation versions 4.5.x sans le correctif de s\u00e9curit\u00e9 ESXi70U3s-24585291","product":{"name":"Cloud Foundation","vendor":{"name":"VMware","scada":false}}},{"description":"VMware Telco Cloud Platorm sans le correctif de s\u00e9curit\u00e9 KB389385","product":{"name":"Telco Cloud Platform","vendor":{"name":"VMware","scada":false}}},{"description":"VMware ESXi versions 7.0 sans le correctif de s\u00e9curit\u00e9 ESXi70U3s-24585291","product":{"name":"ESXi","vendor":{"name":"VMware","scada":false}}},{"description":"VMware Cloud Foundation versions 5.x sans le correctif de s\u00e9curit\u00e9 ESXi80U3d-24585383","product":{"name":"Cloud Foundation","vendor":{"name":"VMware","scada":false}}},{"description":"VMware Fusion 13.x versions ant\u00e9rieures \u00e0 13.6.3","product":{"name":"Fusion","vendor":{"name":"VMware","scada":false}}},{"description":"VMware ESXi versions 8.0  sans le correctif de s\u00e9curit\u00e9 ESXi80U2d-24585300 ou ESXi80U3d-24585383","product":{"name":"ESXi","vendor":{"name":"VMware","scada":false}}},{"description":"VMware Telco Cloud Infrastructure versions 2.x et 3.x sans le correctif de s\u00e9curit\u00e9  KB389385","product":{"name":"Telco Cloud Infrastructure","vendor":{"name":"VMware","scada":false}}},{"description":"VMware Workstation versions 17.x ant\u00e9rieures \u00e0 17.6.3","product":{"name":"Workstation","vendor":{"name":"VMware","scada":false}}}],"affected_systems_content":"","content":"## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des correctifs (cf. section Documentation).","cves":[{"name":"CVE-2025-22224","url":"https://www.cve.org/CVERecord?id=CVE-2025-22224"},{"name":"CVE-2024-38814","url":"https://www.cve.org/CVERecord?id=CVE-2024-38814"},{"name":"CVE-2025-22226","url":"https://www.cve.org/CVERecord?id=CVE-2025-22226"},{"name":"CVE-2025-22225","url":"https://www.cve.org/CVERecord?id=CVE-2025-22225"}],"links":[],"reference":"CERTFR-2025-AVI-0177","revisions":[{"description":"Version initiale","revision_date":"2025-03-05T00:00:00.000000"}],"risks":[{"description":"Ex\u00e9cution de code arbitraire"},{"description":"Contournement de la politique de s\u00e9curit\u00e9"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits VMware. Elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et un contournement de la politique de s\u00e9curit\u00e9.\n\nVMware indique que les vuln\u00e9rabilit\u00e9s CVE-2025-222234, CVE-2025-22225 et  CVE-2025-22226 sont activement exploit\u00e9es.","title":"Multiples vuln\u00e9rabilit\u00e9s dans les produits VMware","vendor_advisories":[{"published_at":"2025-03-04","title":"Bulletin de s\u00e9curit\u00e9 VMware 25466","url":"https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25466"},{"published_at":"2025-03-04","title":"Bulletin de s\u00e9curit\u00e9 VMware 25390","url":"https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390"}]}
