⚠ Actively exploited
Added to CISA KEV on 2025-10-30. Federal agencies required to patch by 2025-11-20. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable..

CVE-2025-41244

CWE-267CWE-28013 documents12 sources
Severity
7.8HIGH
EPSS
0.6%
top 30.76%
CISA KEV
KEV
Added 2025-10-30
Due 2025-11-20
Exploit
No known exploits
Timeline
PublishedSep 29
KEV addedOct 30
KEV dueNov 20
Latest updateDec 3
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages14 packages

NVDvmware/aria_operations8.08.18.5
CVEListV5vmware/vmware_aria_operations8.18.x8.18.5
NVDvmware/tools12.5.012.5.4+1
CVEListV5vmware/vmware_tools13.x.x.x13.0.5.0+1
NVDvmware/open_vm_tools11.2.012.5.4+1

Also affects: Debian Linux 11.0

🔴Vulnerability Details

4
GHSA
GHSA-76fp-m4vp-hxrq: VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability2025-09-29
OSV
CVE-2025-41244: VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability2025-09-29
CVEList
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)2025-09-29
VulnCheck
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability2025

🔍Detection Rules

1
Elastic
Potential CVE-2025-41244 vmtoolsd LPE Exploitation Attempt

📋Vendor Advisories

4
CISA
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability2025-10-30
Ubuntu
Open VM Tools vulnerability2025-09-29
Red Hat
open-vm-tools: Local privilege escalation in open-vm-tools2025-09-29
Debian
CVE-2025-41244: open-vm-tools - VMware Aria Operations and VMware Tools contain a local privilege escalation vul...2025

🕵️Threat Intelligence

3
Securelist
Exploits and vulnerabilities in Q3 20252025-12-03
Bleepingcomputer
CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers2025-10-30
Bleepingcomputer
Chinese hackers exploiting VMware zero-day since October 20242025-09-30
CVE-2025-41244 (HIGH CVSS 7.8) | VMware Aria Operations and VMware T | cvebase.io