7.8
HIGH CVSS 3.1
CVE-2025-41244
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
Description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

INFO

Published Date :

Sept. 29, 2025, 5:15 p.m.

Last Modified :

Oct. 7, 2025, 4:15 p.m.

Remotely Exploit :

No
Affected Products

The following products are affected by CVE-2025-41244 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Vmware tools
2 Vmware cloud_foundation
3 Vmware aria_operations
4 Vmware telco_cloud_platform
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH dcf2e128-44bd-42ed-91e8-88f912c1401d
CVSS 3.1 HIGH [email protected]
Solution
Update VMware Aria Operations and VMware Tools to fix privilege escalation.
  • Update VMware Aria Operations.
  • Update VMware Tools.
  • Apply vendor patches when available.
Public PoC/Exploit Available at Github

CVE-2025-41244 has a 4 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-41244 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

VMware Aria Operations < 4.18.5 & VMware Tools - Local Privilege Escalation

Go

Updated: 2 weeks ago
0 stars 0 fork 0 watcher
Born at : Oct. 6, 2025, 1:35 a.m. This repo has been linked 1 different CVEs too.

Detection for CVE-2025-41244

nuclei aria-operations vulnerability zero-day

Updated: 6 days, 4 hours ago
1 stars 0 fork 0 watcher
Born at : Sept. 30, 2025, 11:40 a.m. This repo has been linked 1 different CVEs too.

A list of all of my starred repos, automated using Github Actions 🌟

github-actions stars

Updated: 2 weeks, 5 days ago
0 stars 0 fork 0 watcher
Born at : Jan. 4, 2023, 11:20 a.m. This repo has been linked 25 different CVEs too.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

security cve exploit poc vulnerability

Updated: 22 hours, 49 minutes ago
7335 stars 1209 fork 1209 watcher
Born at : Dec. 8, 2019, 1:03 p.m. This repo has been linked 827 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-41244 vulnerability anywhere in the article.

  • The Cyber Express
Critical Zero-Day in Oracle E-Business Suite Prompts Urgent Security Updates

Oracle has issued a security alert warning users of a zero-day vulnerability in its widely used Oracle E-Business Suite. Tracked as CVE-2025-61882, this flaw allows unauthenticated, remote attackers t ... Read more

Published Date: Oct 06, 2025 (1 week, 6 days ago)
  • The Cyber Express
Unity Warns Developers of Security Vulnerability Affecting Games on Android, Windows, and Linux Platforms

A recently disclosed security vulnerability in Unity has prompted security updates and, in some cases, game removals across platforms like Steam. The issue affects Unity versions 2017.1 and later, spa ... Read more

Published Date: Oct 06, 2025 (2 weeks ago)
  • The Cyber Express
Critical Splunk Vulnerabilities Expose Platforms to Remote JavaScript Injection and More

Splunk has disclosed six critical security vulnerabilities impacting multiple versions of both Splunk Enterprise and Splunk Cloud Platform. These Splunk vulnerabilities, collectively highlighting seri ... Read more

Published Date: Oct 03, 2025 (2 weeks, 3 days ago)
  • The Cyber Express
Japan’s Beer Taps Fear Running Dry as Cyberattack on Asahi Disrupts Production

Japan’s largest brewery, Asahi Group Holdings, is racing against time as it struggles to recover from a cyberattack that has severely disrupted its operations. The Asahi cyberattack, which was first r ... Read more

Published Date: Oct 03, 2025 (2 weeks, 3 days ago)
  • The Cyber Express
Your Easiest Fix: The 3 Golden Rules for a Password that AI Can’t Crack

October is here, and Cybersecurity Awareness Month 2025 is about to come into being. Department of Homeland Security (DHS) and CISA have initiated this year’s campaign with the theme of ‘Building our ... Read more

Published Date: Oct 03, 2025 (2 weeks, 3 days ago)
  • The Cyber Express
Hackers Claim Breach of Red Hat Customer Data

Hackers claim to have breached a Red Hat GitHub instance and stolen sensitive customer data. The claims were made in Telegram posts by a group calling itself “Crimson Collective,” which said it exfilt ... Read more

Published Date: Oct 02, 2025 (2 weeks, 3 days ago)
  • The Cyber Express
New VMware Vulnerability CVE-2025-41244 Actively Exploited Since October 2024

A newly listed VMware zero-day vulnerability has been actively exploited by Chinese state-sponsored threat actors for almost a year, according to security researchers. The vulnerability, CVE-2025-4124 ... Read more

Published Date: Sep 30, 2025 (2 weeks, 5 days ago)
  • security.nl
'Broadcom dicht VMware-lek dat al een jaar gebruikt is bij aanvallen'

Broadcom heeft een kwetsbaarheid in VMware gedicht die al een jaar bij aanvallen is gebruikt. Dat laat securitybedrijf Nviso in een analyse weten. Hoeveel organisaties slachtoffer van het beveiligings ... Read more

Published Date: Sep 30, 2025 (2 weeks, 5 days ago)
  • BleepingComputer
Chinese hackers exploiting VMware zero-day since October 2024

Broadcom has patched a high-severity privilege escalation vulnerability in its VMware Aria Operations and VMware Tools software, which has been exploited in zero-day attacks since October 2024. While ... Read more

Published Date: Sep 30, 2025 (2 weeks, 5 days ago)
  • BleepingComputer
Broadcom fixes high-severity VMware NSX bugs reported by NSA

Broadcom has released security updates to patch two high-severity VMware NSX vulnerabilities reported by the U.S. National Security Agency (NSA). VMware NSX is a networking virtualization solution wit ... Read more

Published Date: Sep 30, 2025 (2 weeks, 5 days ago)
  • The Hacker News
Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024

Sep 30, 2025Ravie LakshmananZero-Day / Vulnerability A newly patched security flaw impacting Broadcom VMware Tools and VMware Aria Operations has been exploited in the wild as a zero-day since mid-O ... Read more

Published Date: Sep 30, 2025 (2 weeks, 6 days ago)
  • CybersecurityNews
VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution

A zero-day local privilege escalation vulnerability in VMware Tools and VMware Aria Operations is being actively exploited in the wild. The flaw, tracked as CVE-2025-41244, allows an unprivileged loca ... Read more

Published Date: Sep 30, 2025 (2 weeks, 6 days ago)
  • CybersecurityNews
VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root

VMware has released an advisory to address three high-severity vulnerabilities in VMware Aria Operations, VMware Tools, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Inf ... Read more

Published Date: Sep 30, 2025 (2 weeks, 6 days ago)
  • Daily CyberSecurity
Broadcom Patches VMware Flaws: Privilege Escalation and Info Disclosure Vulnerabilities Affect VMware Tools and Aria Operations

Broadcom has released patches addressing three vulnerabilities in VMware Aria Operations and VMware Tools, with severities ranging from Moderate to Important. These flaws—CVE-2025-41244, CVE-2025-4124 ... Read more

Published Date: Sep 30, 2025 (2 weeks, 6 days ago)
  • NVISO Labs
You name it, VMware elevates it (CVE-2025-41244)

On September 29th, 2025, Broadcom disclosed a local privilege escalation vulnerability, CVE-2025-41244, impacting VMware’s guest service discovery features. NVISO has identified zero-day exploitation ... Read more

Published Date: Sep 29, 2025 (2 weeks, 6 days ago)

The following table lists the changes that have been made to the CVE-2025-41244 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Oct. 07, 2025

    Action Type Old Value New Value
    Added Reference https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Sep. 30, 2025

    Action Type Old Value New Value
    Added Reference https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/
  • New CVE Received by [email protected]

    Sep. 29, 2025

    Action Type Old Value New Value
    Added Description VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-267
    Added Reference http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
Vulnerability Scoring Details
Base CVSS Score: 7.8
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact