ZeroHour

CVE-2025-41244

KEV PoC mass1

Local Privilege Escalation in VMware Aria Operations and VMware Tools

CISA: Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

CVSS 3.1
7.8 high
EPSS
8%p95
Published
()
KEV added
AI analysis

CVE-2025-41244 is a local privilege escalation flaw (CWE-267, improper privilege management) in Broadcom's VMware Aria Operations and VMware Tools, arising from privileged operations performed in an unsafe manner. To exploit it, a malicious actor with non-administrative privileges must already have local access to a virtual machine that runs VMware Tools and is managed by Aria Operations with SDMP enabled, at which point they can escalate to root on that same VM. Successful exploitation yields full root-level control (high confidentiality, integrity, and availability impact per the 7.8 CVSS score) on affected guest VMs. Organizations running VMware Aria Operations-managed estates with VMware Tools or Open VM Tools on guests, including VMware Cloud Foundation, Cloud Foundation Operations, Telco Cloud, and Debian-packaged Tools deployments, are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-30, and news reports attribute exploitation to a China-linked actor, with EPSS estimating an 8.4% chance of exploitation within 30 days (95th percentile).

What to do: Apply the Broadcom patches for CVE-2025-41244 per the vendor advisory to Aria Operations and update VMware Tools/Open VM Tools on all managed guests, including bundled components in VMware Cloud Foundation, Cloud Foundation Operations, and Telco Cloud products; follow CISA KEV/BOD 22-01 requirements (patch per vendor instructions or discontinue use for cloud services). As interim mitigation, restrict non-administrative local access on Aria Operations-managed VMs and review whether SDMP is enabled, prioritizing internet-adjacent and high-value guests; Debian users should track the Debian advisory for updated open-vm-tools packages.

Affected
Broadcom VMware Aria Operations
Broadcom VMware Tools
Broadcom VMware Cloud Foundation
Broadcom VMware Cloud Foundation Operations
Broadcom VMware Telco Cloud Infrastructure
Broadcom VMware Telco Cloud Platform
Broadcom Open VM Tools
Debian Linux (open-vm-tools packaging)
Estimated exposure
massmillions of guest VMs run VMware Tools/Open VM Tools; the subset managed by Aria Operations with SDMP enabled is plausibly in the hundreds of thousands of VMs… — VMware Tools ships by default in virtually all vSphere/VCF guest deployments, representing one of the largest hypervisor installed bases in the world, and Aria Operations is a widely deployed management platform whose SDMP-managed guests…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CISA Known Exploited Vulnerability
Affected
Broadcom VMware Aria Operations and VMware Tools
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
vmwaredebian
Products
aria operations, cloud foundation, cloud foundation operations, open vm tools, telco cloud infrastructure, telco cloud platform, debian linux, tools
Weakness
CWE-267
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news