On Thursday, CISA warned U.S. government agencies to secure their systems against attacks exploiting a high-severity vulnerability in Broadcom's VMware Aria Operations and VMware Tools software. Tracked as CVE-2025-41244 and patched one month ago, this vulnerability allows local attackers with non-administrative privileges to a virtual machine (VM) with VMware Tools and managed by Aria Operations with SDMP enabled to escalate privileges to root on the same VM. CISA added the flaw to its Known Exploited Vulnerabilities catalog, which lists security bugs the cybersecurity agency has flagged as exploited in the wild. Federal Civilian Executive Branch (FCEB) agencies now have three weeks, until November 20, to patch their systems against ongoing attacks, as mandated by the Binding Operational Directive (BOD) 22-01 issued in November 2021. FCEB agencies are non-military agencies within the U.S. executive branch, including the Department of Homeland Security, the Department of Energy, the Department of the Treasury, and the Department of Health and Human Services. While BOD 22-01 only applies to federal agencies, CISA urged all organizations to prioritize patching this vulnerability as soon as possible. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA cautioned. "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of t...
CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
BleepingComputer
·Sergiu Gatlan
·Published Oct 30, 2025
·Updated
Affected Software
2 affected components
Broadcom VMware Aria Operations
Broadcom VMware Tools
Frequently Asked Questions
1
What is the main topic of this article?
The main topic is CISA's warning to U.S. government agencies about a high-severity vulnerability in VMware software being exploited by Chinese hackers.
2
What security implications are discussed in the article?
The article discusses the urgent need for government agencies to patch a vulnerability that could lead to exploitation by attackers.
3
What specific vulnerabilities are mentioned in the article?
The vulnerabilities mentioned are tracked as CVE-2025-41244 in VMware Aria Operations and VMware Tools.
4
Who is responsible for the exploitation of the vulnerability?
Chinese hackers are identified as the attackers exploiting the VMware software vulnerability.
5
What products or software are affected by the vulnerability?
The affected products are Broadcom's VMware Aria Operations and VMware Tools.