CVE-2025-41244
published 2025-09-29CVE-2025-41244: VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having…
PriorityP184high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-11-20
Exploited in the wild
EPSS
7.88%
94.1th percentile
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | open-vm-tools | < open-vm-tools 2:12.2.0-1+deb12u4 (bookworm) | open-vm-tools 2:12.2.0-1+deb12u4 (bookworm) |
| vmware | aria_operations | >= 8.0 < 8.18.5 | 8.18.5 |
| vmware | cloud_foundation | 4.0 – 5.2.2 | — |
| vmware | cloud_foundation_operations | — | — |
| vmware | open-vm-tools | >= 0 < 2:11.2.5-2+deb11u5 | 2:11.2.5-2+deb11u5 |
| vmware | open-vm-tools | >= 0 < 2:12.2.0-1+deb12u4 | 2:12.2.0-1+deb12u4 |
| vmware | open-vm-tools | >= 0 < 2:12.5.0-2+deb13u1 | 2:12.5.0-2+deb13u1 |
| vmware | open-vm-tools | >= 0 < 2:13.0.5-1 | 2:13.0.5-1 |
| vmware | open_vm_tools | — | — |
| vmware | open_vm_tools | >= 11.2.0 < 12.5.4 | 12.5.4 |
| vmware | telco_cloud_infrastructure | 2.2 – 3.0 | — |
| vmware | telco_cloud_platform | >= 4.0 < 5.0.1 | 5.0.1 |
| vmware | tools | >= 12.5.0 < 12.5.4 | 12.5.4 |
| vmware | tools | >= 13.0.0.0 < 13.0.5.0 | 13.0.5.0 |
| vmware | vmware_aria_operations | >= 8.18.x < 8.18.5 | 8.18.5 |
| vmware | vmware_cloud_foundation | >= 4.x < 8.18.5 | 8.18.5 |
| vmware | vmware_cloud_foundation | >= 5.x < 8.18.5 | 8.18.5 |
| vmware | vmware_telco_cloud_infrastructure | >= 2.x < 8.18.5 | 8.18.5 |
| vmware | vmware_telco_cloud_infrastructure | >= 3.x < 8.18.5 | 8.18.5 |
| vmware | vmware_telco_cloud_platform | >= 4.x < 8.18.5 | 8.18.5 |
| vmware | vmware_telco_cloud_platform | >= 5.x < 8.18.5 | 8.18.5 |
Detection & IOCsextracted from sources · hover to see the quote
- →Check for presence of the open-vm-tools-sdmp package, which is required for exploitation; use `rpm -q open-vm-tools-sdmp` to verify exposure. ↗
- →Monitor for attacker-controlled binaries being executed from world-writable paths (e.g., /tmp) by the privileged VMware service-discovery routine (open-vm-tools-sdmp). ↗
- →Detect privilege escalation to root originating from an unprivileged user process with a listening socket that is invoked by the VMware service-discovery plugin. ↗
- →CVE-2025-41244 has been actively exploited in the wild since October 2024 by Chinese state-sponsored actors; treat any unpatched VMware Tools + Aria Operations (SDMP enabled) VM as potentially compromised. ↗
- →CISA KEV deadline is 2025-11-20; federal agencies must apply vendor mitigations or discontinue use. ↗
- ·Exploitation requires the open-vm-tools-sdmp package to be installed AND guest service discovery to be enabled; systems without this configuration are not exposed. ↗
- ·The Ubuntu mitigation disables the SDMP get-versions.sh script entirely, meaning version information will no longer be available after patching. ↗
- ·Vulnerability is scoped to local access only; a malicious actor must already have non-administrative local access to the VM. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-76fp-m4vp-hxrq: VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability
ghsa_unreviewed·2025-09-29
CVE-2025-41244 [HIGH] CWE-267 GHSA-76fp-m4vp-hxrq: VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
OSV
CVE-2025-41244: VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability
osv·2025-09-29·CVSS 7.8
CVE-2025-41244 [HIGH] CVE-2025-41244: VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
VulnCheck
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
vulncheck·2025·CVSS 7.8
CVE-2025-41244 [HIGH] CWE-267 Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Affected: Broadcom VMware Aria Operations and VMware Tools
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/;
CISA
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
cisa·2025-10-30·CVSS 7.8
CVE-2025-41244 [HIGH] CWE-267 Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
Vulnerability: Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
Affected: Broadcom VMware Aria Operations and VMware Tools
Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content
Ubuntu
Open VM Tools vulnerability
vendor_ubuntu·2025-09-29
CVE-2025-41244 Open VM Tools vulnerability
Title: Open VM Tools vulnerability
Summary: Open VM Tools could be made to run programs as an administrator.
It was discovered that Open VM Tools incorrectly handled permissions with
version checking. An attacker could possibly use this issue to escalate
privileges inside a virtual machine.
This update disables the SDMP get-versions.sh script, so version
information may no longer be made available.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
open-vm-tools: Local privilege escalation in open-vm-tools
vendor_redhat·2025-09-29·CVSS 7.8
CVE-2025-41244 [HIGH] CWE-280 open-vm-tools: Local privilege escalation in open-vm-tools
open-vm-tools: Local privilege escalation in open-vm-tools
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
A flaw was found in VMWare open-vm-tools. A malicious actor with non-administrative privileges on a guest Virtual Machine (VM) could exploit this vulnerability to gain root privileges on the VM. The issue lies in the service-discovery plugin logic, which can execute attacker-controlled binaries from writable paths such as /tmp. Exploitation requires the open-vm-tools-sdmp package to be installed and guest se
Debian
CVE-2025-41244: open-vm-tools - VMware Aria Operations and VMware Tools contain a local privilege escalation vul...
vendor_debian·2025·CVSS 7.8
CVE-2025-41244 [HIGH] CVE-2025-41244: open-vm-tools - VMware Aria Operations and VMware Tools contain a local privilege escalation vul...
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Scope: local
bookworm: resolved (fixed in 2:12.2.0-1+deb12u4)
bullseye: resolved (fixed in 2:11.2.5-2+deb11u5)
forky: resolved (fixed in 2:13.0.5-1)
sid: resolved (fixed in 2:13.0.5-1)
trixie: resolved (fixed in 2:12.5.0-2+deb13u1)
No public exploits indexed.
Tenable
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
blogs_tenable·2026-05-27
CVE-2023-4966 Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploit
Bleepingcomputer
CISA: VMware ESXi flaw now exploited in ransomware attacks
blogs_bleepingcomputer·2026-02-04·CVSS 9.3
CVE-2025-22225 [CRITICAL] CISA: VMware ESXi flaw now exploited in ransomware attacks
## CISA: VMware ESXi flaw now exploited in ransomware attacks
## Sergiu Gatlan
CISA confirmed on Wednesday that ransomware gangs have begun exploiting a high-severity VMware ESXi sandbox escape vulnerability that was used in zero-day attacks since at least February 2024.
Broadcom patched this ESXi arbitrary-write vulnerability (tracked as CVE-2025-22225) almost one year ago, in March 2025, alongside a memory leak (CVE-2025-22226) and a TOCTOU flaw (CVE-2025-22224), and tagged them all as actively exploited zero-days.
"A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox," Broadcom said about the CVE-2025-22225 flaw.
At the time, the company said that the three vulnerabilities affect VMware ESX products, incl
Bleepingcomputer
CISA says critical VMware RCE flaw now actively exploited
blogs_bleepingcomputer·2026-01-26·CVSS 9.8
CVE-2024-37079 [CRITICAL] CISA says critical VMware RCE flaw now actively exploited
## CISA says critical VMware RCE flaw now actively exploited
## Sergiu Gatlan
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a critical VMware vCenter Server vulnerability as actively exploited and ordered federal agencies to secure their servers within three weeks.
Patched in June 2024, this security flaw ( CVE-2024-37079 ) stems from a heap overflow weakness in the DCERPC protocol implementation of vCenter Server (a Broadcom VMware vSphere management platform that helps admins manage ESXi hosts and virtual machines).
Threat actors with network access to vCenter Server may exploit this vulnerability by sending a specially crafted network packet that can trigger remote code execution in low-complexity attacks that don't require privileges on the targeted s
Securelist
Exploits and vulnerabilities in Q3 2025
blogs_securelist·2025-12-03·CVSS 7.8
CVE-2025-49704 [HIGH] Exploits and vulnerabilities in Q3 2025
Table of Contents
Statistics on registered vulnerabilities
Exploitation statistics
Windows and Linux vulnerability exploitation
Most common published exploits
Vulnerability exploitation in APT attacks
C2 frameworks
Interesting vulnerabilities
ToolShell (CVE-2025-49704 and CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771): insecure deserialization and an authentication bypass
CVE-2025-8088: a directory traversal vulnerability in WinRAR
CVE-2025-41244: a privilege escalation vulnerability in VMware Aria Operations and VMware Tools
Conclusion and advice
Authors
Alexander Kolesnikov
In the third quarter, attackers continued to exploit security flaws in WinRAR, while the total number of registered vulnerabilities grew again. In this report, we examine statistics on published vuln
Securelist
Analyzing the vulnerability landscape in Q3 2025
blogs_securelist·2025-12-03
Analyzing the vulnerability landscape in Q3 2025
Table of Contents
- Statistics on registered vulnerabilities
- Exploitation statistics
- Vulnerability exploitation in APT attacks
- C2 frameworks
- Interesting vulnerabilities
- Conclusion and advice
Authors
- Alexander Kolesnikov
In the third quarter, attackers continued to exploit security flaws in WinRAR, while the total number of registered vulnerabilities grew again. In this report, we examine statistics on published vulnerabilities and exploits, the most common security issues impacting Windows and Linux, and the vulnerabilities being leveraged in APT attacks that lead to the launch of widespread C2 frameworks. The report utilizes anonymized Kaspersky Security Network data, which was consensually provided by our users, as well as information from open sources.
## Statistics on
Bleepingcomputer
CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
blogs_bleepingcomputer·2025-10-30·CVSS 7.8
CVE-2025-41244 [HIGH] CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
## CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
## Sergiu Gatlan
On Thursday, CISA warned U.S. government agencies to secure their systems against attacks exploiting a high-severity vulnerability in Broadcom's VMware Aria Operations and VMware Tools software.
Tracked as CVE-2025-41244 and patched one month ago , this vulnerability allows local attackers with non-administrative privileges to a virtual machine (VM) with VMware Tools and managed by Aria Operations with SDMP enabled to escalate privileges to root on the same VM.
CISA added the flaw to its Known Exploited Vulnerabilities catalog , which lists security bugs the cybersecurity agency has flagged as exploited in the wild. Federal Civilian Executive Branch (FCEB) agencies now have three weeks, until N
Checkpoint
6th October – Threat Intelligence Report
blogs_checkpoint·2025-10-06
CVE-2025-41244 6th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 6th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 6th October, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Red Hat has confirmed a cyber attack that resulted in unauthorized access to one of its GitLab instances. The attackers, Crimson Collective, claim to have stolen approximately 570GB of compressed data. The data includes 28,000 internal repositories, including around 800 Customer Engagement Reports containing sensitive infra
Bleepingcomputer
Chinese hackers exploiting VMware zero-day since October 2024
blogs_bleepingcomputer·2025-09-30·CVSS 9.8
CVE-2025-41244 [CRITICAL] Chinese hackers exploiting VMware zero-day since October 2024
## Chinese hackers exploiting VMware zero-day since October 2024
## Sergiu Gatlan
Broadcom has patched a high-severity privilege escalation vulnerability in its VMware Aria Operations and VMware Tools software, which has been exploited in zero-day attacks since October 2024.
While the American technology giant didn't tag this security bug ( CVE-2025-41244 ) as exploited in the wild, it thanked NVISO threat researcher Maxime Thiebaut for reporting the bug in May.
However, yesterday, the European cybersecurity company disclosed that this vulnerability was first exploited in the wild beginning mid-October 2024 and linked the attacks to the UNC5174 Chinese state-sponsored threat actor.
"To abuse this vulnerability, an unprivileged local attacker can stage a malicious binary within any of
Bleepingcomputer
Broadcom fixes high-severity VMware NSX bugs reported by NSA
blogs_bleepingcomputer·2025-09-30·CVSS 9.3
CVE-2025-41251 [CRITICAL] Broadcom fixes high-severity VMware NSX bugs reported by NSA
## Broadcom fixes high-severity VMware NSX bugs reported by NSA
## Sergiu Gatlan
Broadcom has released security updates to patch two high-severity VMware NSX vulnerabilities reported by the U.S. National Security Agency (NSA).
VMware NSX is a networking virtualization solution within VMware Cloud Foundation that enables administrators to deploy traditional and modern applications in private/hybrid clouds.
The first security flaw reported by the NSA, tracked as CVE-2025-41251 , is due to a weakness in the password recovery mechanism that can let unauthenticated attackers enumerate valid usernames, which could later be used in brute-force attacks.
The second one ( CVE-2025-41252 ) is a username enumeration vulnerability that unauthenticated threat actors can also exploit to enumerate va
Recorded Future
October 2025 CVE Landscape
blogs_recorded_future·CVSS 9.8
[CRITICAL] October 2025 CVE Landscape
# October 2025 CVE Landscape: 32 High-Impact Vulnerabilities Demand Immediate Attention
October 2025 saw a significant escalation in vulnerability activity, with Recorded Future's Insikt Group® identifying 32 high-impact vulnerabilities, double the 16 identified in September's CVE report. Twenty-six of these vulnerabilities scored as Very Critical.
What security teams need to know:
- Microsoft dominates: Eight of 32 vulnerabilities affect Microsoft products, including a critical WSUS deserialization flaw (CVE-2025-59287) now being actively exploited
- CL0P ransomware group exploited an Oracle E-Business Suite zero-day (CVE-2025-61882) for data theft and extortion campaigns
- Legacy vulnerabilities persist: Five of the 14 RCE-enabling vulnerabilities are over a decade old, highlighting c
Bugzilla
CVE-2025-41244 open-vm-tools: Local privilege escalation in open-vm-tools
bugzilla·2025-09-24·CVSS 7.8
CVE-2025-41244 [HIGH] CVE-2025-41244 open-vm-tools: Local privilege escalation in open-vm-tools
CVE-2025-41244 open-vm-tools: Local privilege escalation in open-vm-tools
A flaw was found in open-vm-tools.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:17429 https://access.redhat.com/errata/RHSA-2025:17429
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:17428 https://access.redhat.com/errata/RHSA-2025:17428
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Via RHSA-2025:17446 https://access.redhat.com/errata/RHSA-2025:17446
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.4 Extended Update Support
Via RHSA-2025:17445 https://access.redhat.co
http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149http://www.openwall.com/lists/oss-security/2025/09/29/10https://lists.debian.org/debian-lts-announce/2025/10/msg00000.htmlhttps://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244
2025-09-29
Published
2025-10-30
Added to CISA KEV
Exploited in the wild