CVE-2025-41244: Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
A flaw was found in open-vm-tools.
Other sources
Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
— CISA
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
— Microsoft
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.3.5-3 - Upgrade
Upgrade
open-vm-toolsto a version that resolves this vulnerability.Patch CVE-2025-41244 - Upgrade
Upgrade
Broadcom VMware Aria Operations and VMware Toolsto a version that resolves this vulnerability.Patch VMSA-2025-0015
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41244?
CVE-2025-41244 is considered a local privilege escalation vulnerability that could allow a malicious user to gain elevated permissions.
How do I fix CVE-2025-41244?
To fix CVE-2025-41244, update VMware Aria Operations and VMware Tools to the latest versions provided by VMware.
Who is affected by CVE-2025-41244?
CVE-2025-41244 affects any system running VMware Aria Operations and VMware Tools with SDMP enabled.
What type of vulnerability is CVE-2025-41244?
CVE-2025-41244 is a local privilege escalation vulnerability that can be exploited by non-administrative local users.
What can an attacker do with CVE-2025-41244?
An attacker exploiting CVE-2025-41244 can potentially gain unauthorized access and control over the affected virtual machine.