Broadcom has patched a high-severity privilege escalation vulnerability in its VMware Aria Operations and VMware Tools software, which has been exploited in zero-day attacks since October 2024. While the American technology giant didn't tag this security bug (CVE-2025-41244) as exploited in the wild, it thanked NVISO threat researcher Maxime Thiebaut for reporting the bug in May. However, yesterday, the European cybersecurity company disclosed that this vulnerability was first exploited in the wild beginning mid-October 2024 and linked the attacks to the UNC5174 Chinese state-sponsored threat actor. "To abuse this vulnerability, an unprivileged local attacker can stage a malicious binary within any of the broadly-matched regular expression paths. A simple common location, abused in the wild by UNC5174, is /tmp/httpd," Thiebaut explained. "To ensure the malicious binary is picked up by the VMware service discovery, the binary must be run by the unprivileged user (i.e., show up in the process tree) and open at least a (random) listening socket." NVISO also released a proof-of-concept exploit that demonstrates how attackers can exploit the CVE-2025-41244 flaw to escalate privileges on systems running vulnerable VMware Aria Operations (in credential-based mode) and VMware Tools (in credential-less mode) software, ultimately gaining root-level code execution on the VM. A Broadcom spokesperson was not immediately available for comment when contacted by BleepingComputer earlier tod...
Chinese hackers exploiting VMware zero-day since October 2024
BleepingComputer
·Sergiu Gatlan
·Published Sep 30, 2025
·Updated
Affected Software
2 affected components
Broadcom VMware Aria Operations
Broadcom VMware Tools
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security vulnerability in VMware software that has been exploited by Chinese hackers since October 2024.
2
What security implications are discussed in the article?
The article highlights a high-severity privilege escalation vulnerability that could allow unauthorized access to sensitive data.
3
What products or software are affected by the vulnerability?
The affected software includes Broadcom's VMware Aria Operations and VMware Tools.
4
Who is responsible for the exploitation of the zero-day vulnerability?
Chinese hackers are identified as the group exploiting the zero-day vulnerability.
5
When was the vulnerability first exploited?
The vulnerability has been actively exploited since October 2024.