CVE-2025-41246

VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX.
Configurations

No configuration.

History

29 Sep 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-29 16:15

Updated : 2025-09-29 19:34


NVD link : CVE-2025-41246

Mitre link : CVE-2025-41246

CVE.ORG link : CVE-2025-41246


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization