ZeroHour
Security Affairspublished ()ingested @securityaffairs

Broadcom patches VMware Zero

criticalVulnerability exploited in the wildimportance 60CVE-2025-41244CVE-2025-41245CVE-2025-41246

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-41244
Local Privilege Escalation in VMware Aria Operations and VMware Tools

CVE-2025-41244 is a local privilege escalation flaw (CWE-267, improper privilege management) in Broadcom's VMware Aria Operations and VMware Tools, arising from privileged operations performed in an unsafe manner. To exploit it, a malicious actor with non-administrative privileges must already have local access to a virtual machine that runs VMware Tools and is managed by Aria Operations with SDMP enabled, at which point they can escalate to root on that same VM. Successful exploitation yields full root-level control (high confidentiality, integrity, and availability impact per the 7.8 CVSS score) on affected guest VMs. Organizations running VMware Aria Operations-managed estates with VMware Tools or Open VM Tools on guests, including VMware Cloud Foundation, Cloud Foundation Operations, Telco Cloud, and Debian-packaged Tools deployments, are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-30, and news reports attribute exploitation to a China-linked actor, with EPSS estimating an 8.4% chance of exploitation within 30 days (95th percentile).

Do: Apply the Broadcom patches for CVE-2025-41244 per the vendor advisory to Aria Operations and update VMware Tools/Open VM Tools on all managed guests, including bundled components in VMware Cloud Foundation, Cloud Foundation Operations, and Telco Cloud products; follow CISA KEV/BOD 22-01 requirements (patch per vendor instructions or discontinue use for cloud services). As interim mitigation, restrict non-administrative local access on Aria Operations-managed VMs and review whether SDMP is enabled, prioritizing internet-adjacent and high-value guests; Debian users should track the Debian advisory for updated open-vm-tools packages.

7.88% KEV PoC
  • Broadcom VMware Aria Operations
  • Broadcom VMware Tools
  • Broadcom VMware Cloud Foundation
  • +5 more
massmillions of guest VMs run VMware Tools/Open VM Tools; the subset managed by Aria Operations with SDMP enabled is plausibly in the hundreds of thousands of VMs…
CVE-2025-41245
VMware Aria Operations contains an information disclosure vulnerability.

VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of other users of Aria Operations.

NVD description · AI analysis pending
4.9<1%
CVE-2025-41246
VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls.

VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX.

NVD description · AI analysis pending
7.6<1%
Full article362 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 30, 2025

Broadcom patched six VMware flaws, including CVE-2025-41244, which has been exploited in the wild as a zero-day since mid-October 2024 by UNC5174

Broadcom addressed six VMware vulnerabilities, including four high-severity issues. One of these flaws, tracked as CVE-2025-41244 (CVSS score 7.8), allows local users to escalate to root via VMware Tools and Aria Operations.

“VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. Broadcom has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8.” reads the advisory.A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.”

The vulnerability CVE-2025-41244 has been exploited in the wild as a zero-day since mid-October 2024 by the China-linked threat actor UNC5174.

“On September 29th, 2025, Broadcom disclosed a local privilege escalation vulnerability, CVE-2025-41244, impacting VMware’s guest service discovery features. NVISO has identified zero-day exploitation in the wild beginning mid-October 2024.” reads a report published by NVISO Labs. “Throughout its incident response engagements, NVISO determined with confidence that UNC5174 triggered the local privilege escalation. We can however not assess whether this exploit was part of UNC5174’s capabilities or whether the zero-day’s usage was merely accidental due to its trivialness. UNC5174, a Chinese state-sponsored threat actor, has repeatedly been linked to initial access operations achieved through public exploitation.”

The vulnerability impacts the following versions:

  • VMware Cloud Foundation 4.x and 5.x
  • VMware Cloud Foundation 9.x.x.x
  • VMware Cloud Foundation 13.x.x.x (Windows, Linux)
  • VMware vSphere Foundation 9.x.x.x
  • VMware vSphere Foundation 13.x.x.x (Windows, Linux)
  • VMware Aria Operations 8.x
  • VMware Tools 11.x.x, 12.x.x, and 13.x.x (Windows, Linux)
  • VMware Telco Cloud Platform 4.x and 5.x
  • VMware Telco Cloud Infrastructure 2.x and 3.x

Broadcom also fixed an Information disclosure vulnerability, tracked as CVE-2025-41245, and an improper authorisation vulnerability, tracked as CVE-2025-41246, in VMware products. The patches were released for Aria Ops, Tools, Cloud, and Telco.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Broadcom)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/182816/uncategorized/broadcom-patches-vmware-zero-day-actively-exploited-by-unc5174.html