CVE-2025-41244
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability - [Actively Exploited]
Description
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
INFO
Published Date :
Sept. 29, 2025, 5:15 p.m.
Last Modified :
Nov. 6, 2025, 1:58 p.m.
Remotely Exploit :
No
Source :
[email protected]
CISA KEV (Known Exploited Vulnerabilities)
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.
Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 ; https://nvd.nist.gov/vuln/detail/CVE-2025-41244
Affected Products
The following products are affected by CVE-2025-41244
vulnerability.
Even if cvefeed.io is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | dcf2e128-44bd-42ed-91e8-88f912c1401d | ||||
| CVSS 3.1 | HIGH | [email protected] |
Solution
- Update VMware Aria Operations.
- Update VMware Tools.
- Apply vendor patches when available.
Public PoC/Exploit Available at Github
CVE-2025-41244 has a 7 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2025-41244.
| URL | Resource |
|---|---|
| http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149 | Permissions Required |
| http://www.openwall.com/lists/oss-security/2025/09/29/10 | Mailing List Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html | Mailing List Third Party Advisory |
| https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ | Exploit Third Party Advisory |
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 | US Government Resource |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2025-41244 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2025-41244
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
None
Python
VMware Aria Operations < 4.18.5 & VMware Tools - Local Privilege Escalation
Go
Detection for CVE-2025-41244
nuclei aria-operations vulnerability zero-day
네이버뉴스 가져오기
Python
None
Python
A list of all of my starred repos, automated using Github Actions 🌟
github-actions stars
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
security cve exploit poc vulnerability
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2025-41244 vulnerability anywhere in the article.
-
europa.eu
Cyber Brief 25-11 - October 2025
Cyber Brief (October 2025)November 3, 2025 - Version: 1TLP:CLEARExecutive summaryWe analysed 281 open source reports for this Cyber Brief1.Relating to cyber policy and law enforcement, the European Co ... Read more
-
security.nl
Amerikaanse overheid bevestigt actief misbruik van VMware-lek
Aanvallers maken actief misbruik van een kwetsbaarheid in VMware Aria Operations en VMware Tools waarvoor vorige maand een beveiligingsupdate verscheen, zo meldt het Amerikaanse cyberagentschap CISA. ... Read more
-
The Hacker News
CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
Oct 31, 2025Ravie LakshmananVulnerability / Cyber Attack The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity security flaw impacting Broadcom VMware To ... Read more
-
Daily CyberSecurity
CISA Warns of Active Exploitation in XWiki and VMware Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two new flaws—CVE-2025-24893 in XWiki Platform and CVE-2025-41244 in Broadcom VMware Aria Operations and VMware Tools—to its ... Read more
-
CybersecurityNews
CISA Warns of VMware Tools and Aria Operations 0-Day Vulnerability Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-41244 to its Known Exploited Vulnerabilities catalog. This local privilege escalation flaw affects Broadcom’s VMware Aria ... Read more
-
TheCyberThrone
CISA Adds Dassault DELMIA, XWiki, and VMware Aria Bugs to KEV Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog with significant new entries affecting enterprise and open-source sof ... Read more
-
BleepingComputer
CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
On Thursday, CISA warned U.S. government agencies to secure their systems against attacks exploiting a high-severity vulnerability in Broadcom's VMware Aria Operations and VMware Tools software. Track ... Read more
-
The Cyber Express
Critical Zero-Day in Oracle E-Business Suite Prompts Urgent Security Updates
Oracle has issued a security alert warning users of a zero-day vulnerability in its widely used Oracle E-Business Suite. Tracked as CVE-2025-61882, this flaw allows unauthenticated, remote attackers t ... Read more
-
The Cyber Express
Unity Warns Developers of Security Vulnerability Affecting Games on Android, Windows, and Linux Platforms
A recently disclosed security vulnerability in Unity has prompted security updates and, in some cases, game removals across platforms like Steam. The issue affects Unity versions 2017.1 and later, spa ... Read more
-
The Cyber Express
Critical Splunk Vulnerabilities Expose Platforms to Remote JavaScript Injection and More
Splunk has disclosed six critical security vulnerabilities impacting multiple versions of both Splunk Enterprise and Splunk Cloud Platform. These Splunk vulnerabilities, collectively highlighting seri ... Read more
-
The Cyber Express
Japan’s Beer Taps Fear Running Dry as Cyberattack on Asahi Disrupts Production
Japan’s largest brewery, Asahi Group Holdings, is racing against time as it struggles to recover from a cyberattack that has severely disrupted its operations. The Asahi cyberattack, which was first r ... Read more
-
The Cyber Express
Your Easiest Fix: The 3 Golden Rules for a Password that AI Can’t Crack
October is here, and Cybersecurity Awareness Month 2025 is about to come into being. Department of Homeland Security (DHS) and CISA have initiated this year’s campaign with the theme of ‘Building our ... Read more
-
The Cyber Express
Hackers Claim Breach of Red Hat Customer Data
Hackers claim to have breached a Red Hat GitHub instance and stolen sensitive customer data. The claims were made in Telegram posts by a group calling itself “Crimson Collective,” which said it exfilt ... Read more
-
The Cyber Express
New VMware Vulnerability CVE-2025-41244 Actively Exploited Since October 2024
A newly listed VMware zero-day vulnerability has been actively exploited by Chinese state-sponsored threat actors for almost a year, according to security researchers. The vulnerability, CVE-2025-4124 ... Read more
-
security.nl
'Broadcom dicht VMware-lek dat al een jaar gebruikt is bij aanvallen'
Broadcom heeft een kwetsbaarheid in VMware gedicht die al een jaar bij aanvallen is gebruikt. Dat laat securitybedrijf Nviso in een analyse weten. Hoeveel organisaties slachtoffer van het beveiligings ... Read more
-
BleepingComputer
Chinese hackers exploiting VMware zero-day since October 2024
Broadcom has patched a high-severity privilege escalation vulnerability in its VMware Aria Operations and VMware Tools software, which has been exploited in zero-day attacks since October 2024. While ... Read more
-
BleepingComputer
Broadcom fixes high-severity VMware NSX bugs reported by NSA
Broadcom has released security updates to patch two high-severity VMware NSX vulnerabilities reported by the U.S. National Security Agency (NSA). VMware NSX is a networking virtualization solution wit ... Read more
-
The Hacker News
Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024
Sep 30, 2025Ravie LakshmananZero-Day / Vulnerability A newly patched security flaw impacting Broadcom VMware Tools and VMware Aria Operations has been exploited in the wild as a zero-day since mid-O ... Read more
-
CybersecurityNews
VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution
A zero-day local privilege escalation vulnerability in VMware Tools and VMware Aria Operations is being actively exploited in the wild. The flaw, tracked as CVE-2025-41244, allows an unprivileged loca ... Read more
-
CybersecurityNews
VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root
VMware has released an advisory to address three high-severity vulnerabilities in VMware Aria Operations, VMware Tools, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Inf ... Read more
The following table lists the changes that have been made to the
CVE-2025-41244 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Modified Analysis by [email protected]
Nov. 06, 2025
Action Type Old Value New Value Changed CPE Configuration OR *cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:* versions from (including) 2.2 up to (including) 3.0 *cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* versions from (including) 8.0 up to (excluding) 8.18.5 *cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (including) 5.2.2 *cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:* *cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (excluding) 5.0.1 OR *cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:* versions from (including) 2.2 up to (including) 3.0 *cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* versions from (including) 8.0 up to (excluding) 8.18.5 *cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (including) 5.2.2 *cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:* *cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (excluding) 5.0.1 *cpe:2.3:a:vmware:open_vm_tools:*:*:*:*:*:*:*:* versions from (including) 11.2.0 up to (excluding) 12.5.4 *cpe:2.3:a:vmware:open_vm_tools:13.0.0:*:*:*:*:*:*:* Added Reference Type CVE: http://www.openwall.com/lists/oss-security/2025/09/29/10 Types: Mailing List, Third Party Advisory -
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Nov. 04, 2025
Action Type Old Value New Value Added Reference http://www.openwall.com/lists/oss-security/2025/09/29/10 -
Modified Analysis by [email protected]
Nov. 04, 2025
Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* Added Reference Type CVE: https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html Types: Mailing List, Third Party Advisory -
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Nov. 03, 2025
Action Type Old Value New Value Added Reference https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html -
Initial Analysis by [email protected]
Oct. 31, 2025
Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:* versions from (including) 2.2 up to (including) 3.0 *cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* versions from (including) 8.0 up to (excluding) 8.18.5 *cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (including) 5.2.2 *cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:* *cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (excluding) 5.0.1 Added CPE Configuration AND OR *cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:* versions from (including) 12.5.0 up to (excluding) 12.5.4 *cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:* versions from (including) 13.0.0.0 up to (excluding) 13.0.5.0 OR cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* Added Reference Type VMware: http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149 Types: Permissions Required Added Reference Type CISA-ADP: https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ Types: Exploit, Third Party Advisory Added Reference Type CISA-ADP: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 Types: Vendor Advisory Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 Types: US Government Resource -
CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725
Oct. 31, 2025
Action Type Old Value New Value Added Date Added 2025-10-30 Added Due Date 2025-11-20 Added Required Action Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Added Vulnerability Name Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Oct. 30, 2025
Action Type Old Value New Value Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Oct. 07, 2025
Action Type Old Value New Value Added Reference https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Sep. 30, 2025
Action Type Old Value New Value Added Reference https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ -
New CVE Received by [email protected]
Sep. 29, 2025
Action Type Old Value New Value Added Description VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM. Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Added CWE CWE-267 Added Reference http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149