CVE-2025-41244: Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

Published Sep 24, 2025
·
Updated

A flaw was found in open-vm-tools.

Other sources

Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CISA

VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)

Microsoft

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

NVD

Affected Software

15 affected componentsFixes available
VMware open-vm-tools
Broadcom VMware Aria Operations and VMware Tools
VMware Aria Operations>=8.0<8.18.5
VMware Cloud Foundation>=4.0<=5.2.2
VMware Cloud Foundation Operations=9.0
VMware Open Vm Tools>=11.2.0<12.5.4
VMware Open Vm Tools=13.0.0
VMware Telco Cloud Infrastructure>=2.2<=3.0
VMware Telco Cloud Platform>=4.0<5.0.1
All of the following
Any of the following
VMware Tools>=12.5.0<12.5.4
VMware Tools>=13.0.0.0<13.0.5.0
Any of the following
Linux Linux kernel
Microsoft Windows
Debian Debian Linux=11.0
Microsoft azl3 open-vm-tools 12.3.5-2<12.3.5-3
12.3.5-3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 12.3.5-3
  2. Upgrade

    Upgrade open-vm-tools to a version that resolves this vulnerability.

    Patch CVE-2025-41244
  3. Upgrade

    Upgrade Broadcom VMware Aria Operations and VMware Tools to a version that resolves this vulnerability.

    Patch VMSA-2025-0015

Event History

Sep 24, 2025
Data Sourced
via Red Hat·03:28 AM
DescriptionSeverityAffected Software
Sep 29, 2025
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 30, 2025
News Published
via BleepingComputer·12:10 PM
News Published
via BleepingComputer·12:10 PM
News Published
via BleepingComputer·02:54 PM
Oct 30, 2025
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
News Published
via BleepingComputer·08:01 PM
Jan 26, 2026
News Published
via BleepingComputer·11:49 AM
Feb 4, 2026
News Published
via BleepingComputer·05:38 PM
Jul 24, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-41244?

CVE-2025-41244 is considered a local privilege escalation vulnerability that could allow a malicious user to gain elevated permissions.

2

How do I fix CVE-2025-41244?

To fix CVE-2025-41244, update VMware Aria Operations and VMware Tools to the latest versions provided by VMware.

3

Who is affected by CVE-2025-41244?

CVE-2025-41244 affects any system running VMware Aria Operations and VMware Tools with SDMP enabled.

4

What type of vulnerability is CVE-2025-41244?

CVE-2025-41244 is a local privilege escalation vulnerability that can be exploited by non-administrative local users.

5

What can an attacker do with CVE-2025-41244?

An attacker exploiting CVE-2025-41244 can potentially gain unauthorized access and control over the affected virtual machine.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203