Vulnerability Description
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Aria Operations | >= 8.0, < 8.18.5 |
| Vmware | Cloud Foundation | >= 4.0, <= 5.2.2 |
| Vmware | Cloud Foundation Operations | 9.0 |
| Vmware | Open Vm Tools | >= 11.2.0, < 12.5.4 |
| Vmware | Telco Cloud Infrastructure | >= 2.2, <= 3.0 |
| Vmware | Telco Cloud Platform | >= 4.0, < 5.0.1 |
| Debian | Debian Linux | 11.0 |
| Vmware | Tools | >= 12.5.0, < 12.5.4 |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- http://support.broadcom.com/group/ecx/support-content-view/-/support-content/SecPermissions Required
- http://www.openwall.com/lists/oss-security/2025/09/29/10Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00000.htmlMailing ListThird Party Advisory
- https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ExploitThird Party Advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/conVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-US Government Resource
FAQ
What is CVE-2025-41244?
CVE-2025-41244 is a vulnerability with a CVSS score of 7.8 (HIGH). VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed...
How severe is CVE-2025-41244?
CVE-2025-41244 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-41244?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Aria Operations, Vmware Cloud Foundation, Vmware Cloud Foundation Operations, Vmware Open Vm Tools, Vmware Telco Cloud Infrastructure.