• News/
  • https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-vmware-tools-flaw-exploited-since-october-2024/

CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers

BleepingComputer
·
Sergiu Gatlan
·
Published Oct 30, 2025
·
Updated

On Thursday, CISA warned U.S. government agencies to secure their systems against attacks exploiting a high-severity vulnerability in Broadcom's VMware Aria Operations and VMware Tools software. Tracked as CVE-2025-41244 and patched one month ago, this vulnerability allows local attackers with non-administrative privileges to a virtual machine (VM) with VMware Tools and managed by Aria Operations with SDMP enabled to escalate privileges to root on the same VM. CISA added the flaw to its Known Exploited Vulnerabilities catalog, which lists security bugs the cybersecurity agency has flagged as exploited in the wild. Federal Civilian Executive Branch (FCEB) agencies now have three weeks, until November 20, to patch their systems against ongoing attacks, as mandated by the Binding Operational Directive (BOD) 22-01 issued in November 2021. FCEB agencies are non-military agencies within the U.S. executive branch, including the Department of Homeland Security, the Department of Energy, the Department of the Treasury, and the Department of Health and Human Services. While BOD 22-01 only applies to federal agencies, CISA urged all organizations to prioritize patching this vulnerability as soon as possible. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA cautioned. "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of t...

Read full article

Affected Software

2 affected components
Broadcom VMware Aria Operations
Broadcom VMware Tools
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The main topic is CISA's warning to U.S. government agencies about a high-severity vulnerability in VMware software being exploited by Chinese hackers.

2

What security implications are discussed in the article?

The article discusses the urgent need for government agencies to patch a vulnerability that could lead to exploitation by attackers.

3

What specific vulnerabilities are mentioned in the article?

The vulnerabilities mentioned are tracked as CVE-2025-41244 in VMware Aria Operations and VMware Tools.

4

Who is responsible for the exploitation of the vulnerability?

Chinese hackers are identified as the attackers exploiting the VMware software vulnerability.

5

What products or software are affected by the vulnerability?

The affected products are Broadcom's VMware Aria Operations and VMware Tools.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203