Security Affairs newsletter Round 544 by Pierluigi Paganini – INTERNATIONAL EDITION
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-41244 | Local Privilege Escalation in VMware Aria Operations and VMware Tools CVE-2025-41244 is a local privilege escalation flaw (CWE-267, improper privilege management) in Broadcom's VMware Aria Operations and VMware Tools, arising from privileged operations performed in an unsafe manner. To exploit it, a malicious actor with non-administrative privileges must already have local access to a virtual machine that runs VMware Tools and is managed by Aria Operations with SDMP enabled, at which point they can escalate to root on that same VM. Successful exploitation yields full root-level control (high confidentiality, integrity, and availability impact per the 7.8 CVSS score) on affected guest VMs. Organizations running VMware Aria Operations-managed estates with VMware Tools or Open VM Tools on guests, including VMware Cloud Foundation, Cloud Foundation Operations, Telco Cloud, and Debian-packaged Tools deployments, are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-30, and news reports attribute exploitation to a China-linked actor, with EPSS estimating an 8.4% chance of exploitation within 30 days (95th percentile). Do: Apply the Broadcom patches for CVE-2025-41244 per the vendor advisory to Aria Operations and update VMware Tools/Open VM Tools on all managed guests, including bundled components in VMware Cloud Foundation, Cloud Foundation Operations, and Telco Cloud products; follow CISA KEV/BOD 22-01 requirements (patch per vendor instructions or discontinue use for cloud services). As interim mitigation, restrict non-administrative local access on Aria Operations-managed VMs and review whether SDMP is enabled, prioritizing internet-adjacent and high-value guests; Debian users should track the Debian advisory for updated open-vm-tools packages. | 7.8 | 8% | KEV PoC |
| massmillions of guest VMs run VMware Tools/Open VM Tools; the subset managed by Aria Operations with SDMP enabled is plausibly in the hundreds of thousands of VMs… |
Full article701 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Woman convicted following world’s largest crypto seizure
‘You’ll never need to work again’: Criminals offer reporter money to hack BBC
Red Hat confirms security incident after hackers claim GitHub breach
Researchers Say They Flagged Cyber Flaws at Jaguar Ahead of Crippling Breach
Oracle Apps Exploited by Hackers in New Extortion Campaign
Silent Smishing : The Hidden Abuse of Cellular Router APIs
Malware
First Malicious MCP in the Wild: The Postmark Backdoor That’s Stealing Your Emails
Klopatra: exposing a new Android banking trojan operation with roots in Turkey
Check Your Socks – A Deep Dive into soopsocks PyPI Package
New spyware campaigns target privacy-conscious Android users in the UAE
Rhadamanthys 0.9.x – walk through the updates
Hacking
AppSuite, OneStart & ManualFinder: The Nexus of Deception
Apple fixes critical font processing bug. Update now!
Why hackers are targeting the world’s shipping
HackerOne Report Finds 210% Spike in AI Vulnerability Reports Amid Rise of AI Autonomy
Palo Alto Scanning Surges ~500% in 48 Hours, Marking 90-Day High
WireTap: Breaking Server SGX via DRAM Bus Interposition
Battering RAM Low-Cost Interposer Attacks on Confidential Computing
OneLogin, Many Secrets: Clutch Uncovers Critical API Vulnerability Exposing Client Credentials
Intelligence and Information Warfare
Two Dutch teens arrested in rare Russian espionage case
Pro-EU party in Moldova set to win vote mired in claims of Russian interference
You name it, VMware elevates it (CVE-2025-41244)
Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR Malware Suite
SVG Phishing hits Ukraine with Amatera Stealer, PureMiner
CABINETRAT backdoor used by UAC-0245 for targeted cyberattacks against SOU (CERT-UA#17479)
Cavalry Werewolf raids Russia’s public sector with trusted relationship attacks
Confucius Espionage: From Stealer to Backdoor
Cybersecurity
Harrods warns customers their data may have been stolen in IT breach
Government backs Jaguar Land Rover with £1.5 billion loan guarantee
WestJet confirms recent breach exposed customers’ passports
AI Agents Are Eroding the Foundations of Cybersecurity
Feds cut funding to program that shared cyber threat info with local governments
California enacts AI safety law targeting tech giants
Package Maintainers Call for Improvements to GitHub’s New npm Security Plan
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/182951/breaking-news/security-affairs-newsletter-round-544-by-pierluigi-paganini-international-edition.html