CVE-2025-41244

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/09/29/10 -

04 Nov 2025, 14:53

Type Values Removed Values Added
First Time Debian debian Linux
Debian
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html - () https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html - Mailing List, Third Party Advisory

03 Nov 2025, 19:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html -

31 Oct 2025, 14:36

Type Values Removed Values Added
References () http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149 - () http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149 - Permissions Required
References () https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ - () https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ - Exploit, Third Party Advisory
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 - Vendor Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 - US Government Resource
First Time Vmware cloud Foundation Operations
Linux
Vmware aria Operations
Vmware tools
Microsoft
Vmware telco Cloud Platform
Microsoft windows
Vmware cloud Foundation
Vmware
Vmware telco Cloud Infrastructure
Linux linux Kernel
CPE cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

30 Oct 2025, 18:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 -

07 Oct 2025, 16:15

Type Values Removed Values Added
References
  • () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 -

30 Sep 2025, 13:15

Type Values Removed Values Added
References
  • () https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ -

29 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-29 17:15

Updated : 2025-11-04 22:16


NVD link : CVE-2025-41244

Mitre link : CVE-2025-41244

CVE.ORG link : CVE-2025-41244


JSON object : View

Products Affected

vmware

  • aria_operations
  • telco_cloud_infrastructure
  • tools
  • cloud_foundation
  • telco_cloud_platform
  • cloud_foundation_operations

microsoft

  • windows

debian

  • debian_linux

linux

  • linux_kernel
CWE
CWE-267

Privilege Defined With Unsafe Actions