Known Exploited Vulnerability
7.8
HIGH CVSS 3.1
CVE-2025-41244
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability - [Actively Exploited]
Description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

INFO

Published Date :

Sept. 29, 2025, 5:15 p.m.

Last Modified :

Nov. 6, 2025, 1:58 p.m.

Remotely Exploit :

No
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Required Action :

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes :

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 ; https://nvd.nist.gov/vuln/detail/CVE-2025-41244

Affected Products

The following products are affected by CVE-2025-41244 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Vmware tools
2 Vmware cloud_foundation
3 Vmware open_vm_tools
4 Vmware aria_operations
5 Vmware telco_cloud_platform
6 Vmware telco_cloud_infrastructure
7 Vmware cloud_foundation_operations
1 Linux linux_kernel
1 Debian debian_linux
1 Microsoft windows
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH dcf2e128-44bd-42ed-91e8-88f912c1401d
CVSS 3.1 HIGH [email protected]
Solution
Update VMware Aria Operations and VMware Tools to fix privilege escalation.
  • Update VMware Aria Operations.
  • Update VMware Tools.
  • Apply vendor patches when available.
Public PoC/Exploit Available at Github

CVE-2025-41244 has a 7 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-41244 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

Python

Updated: 16 hours, 5 minutes ago
0 stars 0 fork 0 watcher
Born at : Nov. 2, 2025, 4:21 a.m. This repo has been linked 1 different CVEs too.

VMware Aria Operations < 4.18.5 & VMware Tools - Local Privilege Escalation

Go

Updated: 1 month ago
0 stars 0 fork 0 watcher
Born at : Oct. 6, 2025, 1:35 a.m. This repo has been linked 1 different CVEs too.

Detection for CVE-2025-41244

nuclei aria-operations vulnerability zero-day

Updated: 3 weeks, 2 days ago
1 stars 0 fork 0 watcher
Born at : Sept. 30, 2025, 11:40 a.m. This repo has been linked 1 different CVEs too.

네이버뉴스 가져오기

Python

Updated: 4 days, 14 hours ago
0 stars 0 fork 0 watcher
Born at : Aug. 6, 2025, 2:43 a.m. This repo has been linked 1 different CVEs too.

None

Python

Updated: 14 hours, 14 minutes ago
1 stars 0 fork 0 watcher
Born at : Oct. 29, 2024, 8:10 p.m. This repo has been linked 10 different CVEs too.

A list of all of my starred repos, automated using Github Actions 🌟

github-actions stars

Updated: 5 days, 18 hours ago
0 stars 0 fork 0 watcher
Born at : Jan. 4, 2023, 11:20 a.m. This repo has been linked 30 different CVEs too.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

security cve exploit poc vulnerability

Updated: 13 hours, 44 minutes ago
7367 stars 1216 fork 1216 watcher
Born at : Dec. 8, 2019, 1:03 p.m. This repo has been linked 828 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-41244 vulnerability anywhere in the article.

  • europa.eu
Cyber Brief 25-11 - October 2025

Cyber Brief (October 2025)November 3, 2025 - Version: 1TLP:CLEARExecutive summaryWe analysed 281 open source reports for this Cyber Brief1.Relating to cyber policy and law enforcement, the European Co ... Read more

Published Date: Nov 01, 2025 (5 days, 4 hours ago)
  • security.nl
Amerikaanse overheid bevestigt actief misbruik van VMware-lek

Aanvallers maken actief misbruik van een kwetsbaarheid in VMware Aria Operations en VMware Tools waarvoor vorige maand een beveiligingsupdate verscheen, zo meldt het Amerikaanse cyberagentschap CISA. ... Read more

Published Date: Oct 31, 2025 (6 days, 10 hours ago)
  • The Hacker News
CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks

Oct 31, 2025Ravie LakshmananVulnerability / Cyber Attack The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity security flaw impacting Broadcom VMware To ... Read more

Published Date: Oct 31, 2025 (6 days, 13 hours ago)
  • Daily CyberSecurity
CISA Warns of Active Exploitation in XWiki and VMware Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two new flaws—CVE-2025-24893 in XWiki Platform and CVE-2025-41244 in Broadcom VMware Aria Operations and VMware Tools—to its ... Read more

Published Date: Oct 31, 2025 (6 days, 18 hours ago)
  • CybersecurityNews
CISA Warns of VMware Tools and Aria Operations 0-Day Vulnerability Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-41244 to its Known Exploited Vulnerabilities catalog. This local privilege escalation flaw affects Broadcom’s VMware Aria ... Read more

Published Date: Oct 31, 2025 (6 days, 19 hours ago)
  • TheCyberThrone
CISA Adds Dassault DELMIA, XWiki, and VMware Aria Bugs to KEV Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog with significant new entries affecting enterprise and open-source sof ... Read more

Published Date: Oct 31, 2025 (6 days, 19 hours ago)
  • BleepingComputer
CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers

On Thursday, CISA warned U.S. government agencies to secure their systems against attacks exploiting a high-severity vulnerability in Broadcom's VMware Aria Operations and VMware Tools software. Track ... Read more

Published Date: Oct 30, 2025 (1 week ago)
  • The Cyber Express
Critical Zero-Day in Oracle E-Business Suite Prompts Urgent Security Updates

Oracle has issued a security alert warning users of a zero-day vulnerability in its widely used Oracle E-Business Suite. Tracked as CVE-2025-61882, this flaw allows unauthenticated, remote attackers t ... Read more

Published Date: Oct 06, 2025 (1 month ago)
  • The Cyber Express
Unity Warns Developers of Security Vulnerability Affecting Games on Android, Windows, and Linux Platforms

A recently disclosed security vulnerability in Unity has prompted security updates and, in some cases, game removals across platforms like Steam. The issue affects Unity versions 2017.1 and later, spa ... Read more

Published Date: Oct 06, 2025 (1 month ago)
  • The Cyber Express
Critical Splunk Vulnerabilities Expose Platforms to Remote JavaScript Injection and More

Splunk has disclosed six critical security vulnerabilities impacting multiple versions of both Splunk Enterprise and Splunk Cloud Platform. These Splunk vulnerabilities, collectively highlighting seri ... Read more

Published Date: Oct 03, 2025 (1 month ago)
  • The Cyber Express
Japan’s Beer Taps Fear Running Dry as Cyberattack on Asahi Disrupts Production

Japan’s largest brewery, Asahi Group Holdings, is racing against time as it struggles to recover from a cyberattack that has severely disrupted its operations. The Asahi cyberattack, which was first r ... Read more

Published Date: Oct 03, 2025 (1 month ago)
  • The Cyber Express
Your Easiest Fix: The 3 Golden Rules for a Password that AI Can’t Crack

October is here, and Cybersecurity Awareness Month 2025 is about to come into being. Department of Homeland Security (DHS) and CISA have initiated this year’s campaign with the theme of ‘Building our ... Read more

Published Date: Oct 03, 2025 (1 month ago)
  • The Cyber Express
Hackers Claim Breach of Red Hat Customer Data

Hackers claim to have breached a Red Hat GitHub instance and stolen sensitive customer data. The claims were made in Telegram posts by a group calling itself “Crimson Collective,” which said it exfilt ... Read more

Published Date: Oct 02, 2025 (1 month ago)
  • The Cyber Express
New VMware Vulnerability CVE-2025-41244 Actively Exploited Since October 2024

A newly listed VMware zero-day vulnerability has been actively exploited by Chinese state-sponsored threat actors for almost a year, according to security researchers. The vulnerability, CVE-2025-4124 ... Read more

Published Date: Sep 30, 2025 (1 month, 1 week ago)
  • security.nl
'Broadcom dicht VMware-lek dat al een jaar gebruikt is bij aanvallen'

Broadcom heeft een kwetsbaarheid in VMware gedicht die al een jaar bij aanvallen is gebruikt. Dat laat securitybedrijf Nviso in een analyse weten. Hoeveel organisaties slachtoffer van het beveiligings ... Read more

Published Date: Sep 30, 2025 (1 month, 1 week ago)
  • BleepingComputer
Chinese hackers exploiting VMware zero-day since October 2024

Broadcom has patched a high-severity privilege escalation vulnerability in its VMware Aria Operations and VMware Tools software, which has been exploited in zero-day attacks since October 2024. While ... Read more

Published Date: Sep 30, 2025 (1 month, 1 week ago)
  • BleepingComputer
Broadcom fixes high-severity VMware NSX bugs reported by NSA

Broadcom has released security updates to patch two high-severity VMware NSX vulnerabilities reported by the U.S. National Security Agency (NSA). VMware NSX is a networking virtualization solution wit ... Read more

Published Date: Sep 30, 2025 (1 month, 1 week ago)
  • The Hacker News
Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024

Sep 30, 2025Ravie LakshmananZero-Day / Vulnerability A newly patched security flaw impacting Broadcom VMware Tools and VMware Aria Operations has been exploited in the wild as a zero-day since mid-O ... Read more

Published Date: Sep 30, 2025 (1 month, 1 week ago)
  • CybersecurityNews
VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution

A zero-day local privilege escalation vulnerability in VMware Tools and VMware Aria Operations is being actively exploited in the wild. The flaw, tracked as CVE-2025-41244, allows an unprivileged loca ... Read more

Published Date: Sep 30, 2025 (1 month, 1 week ago)
  • CybersecurityNews
VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root

VMware has released an advisory to address three high-severity vulnerabilities in VMware Aria Operations, VMware Tools, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Inf ... Read more

Published Date: Sep 30, 2025 (1 month, 1 week ago)

The following table lists the changes that have been made to the CVE-2025-41244 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Modified Analysis by [email protected]

    Nov. 06, 2025

    Action Type Old Value New Value
    Changed CPE Configuration OR *cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:* versions from (including) 2.2 up to (including) 3.0 *cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* versions from (including) 8.0 up to (excluding) 8.18.5 *cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (including) 5.2.2 *cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:* *cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (excluding) 5.0.1 OR *cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:* versions from (including) 2.2 up to (including) 3.0 *cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* versions from (including) 8.0 up to (excluding) 8.18.5 *cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (including) 5.2.2 *cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:* *cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (excluding) 5.0.1 *cpe:2.3:a:vmware:open_vm_tools:*:*:*:*:*:*:*:* versions from (including) 11.2.0 up to (excluding) 12.5.4 *cpe:2.3:a:vmware:open_vm_tools:13.0.0:*:*:*:*:*:*:*
    Added Reference Type CVE: http://www.openwall.com/lists/oss-security/2025/09/29/10 Types: Mailing List, Third Party Advisory
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 04, 2025

    Action Type Old Value New Value
    Added Reference http://www.openwall.com/lists/oss-security/2025/09/29/10
  • Modified Analysis by [email protected]

    Nov. 04, 2025

    Action Type Old Value New Value
    Added CPE Configuration OR *cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
    Added Reference Type CVE: https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html Types: Mailing List, Third Party Advisory
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 03, 2025

    Action Type Old Value New Value
    Added Reference https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html
  • Initial Analysis by [email protected]

    Oct. 31, 2025

    Action Type Old Value New Value
    Added CPE Configuration OR *cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:* versions from (including) 2.2 up to (including) 3.0 *cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* versions from (including) 8.0 up to (excluding) 8.18.5 *cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (including) 5.2.2 *cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:* *cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (excluding) 5.0.1
    Added CPE Configuration AND OR *cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:* versions from (including) 12.5.0 up to (excluding) 12.5.4 *cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:* versions from (including) 13.0.0.0 up to (excluding) 13.0.5.0 OR cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
    Added Reference Type VMware: http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149 Types: Permissions Required
    Added Reference Type CISA-ADP: https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ Types: Exploit, Third Party Advisory
    Added Reference Type CISA-ADP: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 Types: Vendor Advisory
    Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 Types: US Government Resource
  • CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725

    Oct. 31, 2025

    Action Type Old Value New Value
    Added Date Added 2025-10-30
    Added Due Date 2025-11-20
    Added Required Action Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    Added Vulnerability Name Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Oct. 30, 2025

    Action Type Old Value New Value
    Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Oct. 07, 2025

    Action Type Old Value New Value
    Added Reference https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Sep. 30, 2025

    Action Type Old Value New Value
    Added Reference https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/
  • New CVE Received by [email protected]

    Sep. 29, 2025

    Action Type Old Value New Value
    Added Description VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-267
    Added Reference http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
Vulnerability Scoring Details
Base CVSS Score: 7.8
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact