cbcvebase.
CVE-2025-41244
published 2025-09-29

CVE-2025-41244: VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having…

PriorityP184high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-11-20
Exploited in the wild
EPSS
7.88%
94.1th percentile
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianopen-vm-tools< open-vm-tools 2:12.2.0-1+deb12u4 (bookworm)open-vm-tools 2:12.2.0-1+deb12u4 (bookworm)
vmwarearia_operations>= 8.0 < 8.18.58.18.5
vmwarecloud_foundation4.0 – 5.2.2
vmwarecloud_foundation_operations
vmwareopen-vm-tools>= 0 < 2:11.2.5-2+deb11u52:11.2.5-2+deb11u5
vmwareopen-vm-tools>= 0 < 2:12.2.0-1+deb12u42:12.2.0-1+deb12u4
vmwareopen-vm-tools>= 0 < 2:12.5.0-2+deb13u12:12.5.0-2+deb13u1
vmwareopen-vm-tools>= 0 < 2:13.0.5-12:13.0.5-1
vmwareopen_vm_tools
vmwareopen_vm_tools>= 11.2.0 < 12.5.412.5.4
vmwaretelco_cloud_infrastructure2.2 – 3.0
vmwaretelco_cloud_platform>= 4.0 < 5.0.15.0.1
vmwaretools>= 12.5.0 < 12.5.412.5.4
vmwaretools>= 13.0.0.0 < 13.0.5.013.0.5.0
vmwarevmware_aria_operations>= 8.18.x < 8.18.58.18.5
vmwarevmware_cloud_foundation>= 4.x < 8.18.58.18.5
vmwarevmware_cloud_foundation>= 5.x < 8.18.58.18.5
vmwarevmware_telco_cloud_infrastructure>= 2.x < 8.18.58.18.5
vmwarevmware_telco_cloud_infrastructure>= 3.x < 8.18.58.18.5
vmwarevmware_telco_cloud_platform>= 4.x < 8.18.58.18.5
vmwarevmware_telco_cloud_platform>= 5.x < 8.18.58.18.5

Detection & IOCsextracted from sources · hover to see the quote

processvmware-toolbox-cmd config set servicediscovery disabled true
filenameget-versions.sh
  • Check for presence of the open-vm-tools-sdmp package, which is required for exploitation; use `rpm -q open-vm-tools-sdmp` to verify exposure.
  • Monitor for attacker-controlled binaries being executed from world-writable paths (e.g., /tmp) by the privileged VMware service-discovery routine (open-vm-tools-sdmp).
  • Detect privilege escalation to root originating from an unprivileged user process with a listening socket that is invoked by the VMware service-discovery plugin.
  • CVE-2025-41244 has been actively exploited in the wild since October 2024 by Chinese state-sponsored actors; treat any unpatched VMware Tools + Aria Operations (SDMP enabled) VM as potentially compromised.
  • CISA KEV deadline is 2025-11-20; federal agencies must apply vendor mitigations or discontinue use.
  • ·Exploitation requires the open-vm-tools-sdmp package to be installed AND guest service discovery to be enabled; systems without this configuration are not exposed.
  • ·The Ubuntu mitigation disables the SDMP get-versions.sh script entirely, meaning version information will no longer be available after patching.
  • ·Vulnerability is scoped to local access only; a malicious actor must already have non-administrative local access to the VM.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.