CVE-2025-41244

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:open_vm_tools:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:open_vm_tools:13.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

06 Nov 2025, 13:58

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2025/09/29/10 - () http://www.openwall.com/lists/oss-security/2025/09/29/10 - Mailing List, Third Party Advisory
First Time Vmware open Vm Tools
CPE cpe:2.3:a:vmware:open_vm_tools:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:open_vm_tools:13.0.0:*:*:*:*:*:*:*

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/09/29/10 -

04 Nov 2025, 14:53

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
First Time Debian debian Linux
Debian
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html - () https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html - Mailing List, Third Party Advisory

03 Nov 2025, 19:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html -

31 Oct 2025, 14:36

Type Values Removed Values Added
CPE cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:*
References () http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149 - () http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149 - Permissions Required
References () https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ - () https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ - Exploit, Third Party Advisory
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 - Vendor Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 - US Government Resource
First Time Vmware tools
Vmware cloud Foundation Operations
Vmware
Microsoft windows
Vmware telco Cloud Platform
Linux
Linux linux Kernel
Vmware cloud Foundation
Microsoft
Vmware telco Cloud Infrastructure
Vmware aria Operations

30 Oct 2025, 18:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 -

07 Oct 2025, 16:15

Type Values Removed Values Added
References
  • () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 -

30 Sep 2025, 13:15

Type Values Removed Values Added
References
  • () https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ -

29 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-29 17:15

Updated : 2025-11-06 13:58


NVD link : CVE-2025-41244

Mitre link : CVE-2025-41244

CVE.ORG link : CVE-2025-41244


JSON object : View

Products Affected

vmware

  • tools
  • telco_cloud_platform
  • aria_operations
  • cloud_foundation_operations
  • open_vm_tools
  • cloud_foundation
  • telco_cloud_infrastructure

microsoft

  • windows

debian

  • debian_linux

linux

  • linux_kernel
CWE
CWE-267

Privilege Defined With Unsafe Actions