← Vulnerability feed

Vulnerability record · CVE-2025-41244 · published 29 September 2025

CVE-2025-41244: VMware Aria Operations and Tools local privilege escalation to root

Vmware · Aria Operations

VMware Aria Operations and VMware Tools contain a local privilege escalation flaw where a non-administrative local actor on a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled can escalate to root on that same VM. It matters because the affected components are widely deployed in virtualized and cloud environments, and the flaw is listed in CISA KEV with a federal remediation deadline.

7.8 CVSS 3.1 High CISA KEV since 30 Oct 2025 EPSS 8.4% · top 5.2% CWE-267 · CWE-267
7.8CVSS 3.1 base score
8.4%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
8Affected product versions listed by NVD
6References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is a local privilege escalation to root with a CVSS of 7.8, listed in CISA KEV with a near-term federal due date and public exploit reference, though it requires an existing local foothold and specific SDMP configuration.

What it is

VMware Aria Operations and VMware Tools contain a local privilege escalation flaw where a non-administrative local actor on a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled can escalate to root on that same VM. It matters because the affected components are widely deployed in virtualized and cloud environments, and the flaw is listed in CISA KEV with a federal remediation deadline.

Impact

An attacker with only non-administrative local access gains full root privileges on the affected VM, enabling complete control of that guest, including data access, persistence and further lateral movement.

Attack surface

The vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the attacker must already have a foothold on the guest VM and the environment must have VMware Tools managed by Aria Operations with SDMP enabled.

Exploitation

CVE-2025-41244 is in CISA KEV (added 2025-10-30, due 2025-11-20) and a third-party reference is tagged Exploit, indicating public exploitation knowledge; EPSS 30-day probability is about 8.4 percent (94.7th percentile). No ransomware campaign use is documented.

What to do

  • Apply the vendor updates from Broadcom VMSA-2025-0015 for VMware Aria Operations and VMware Tools as the first action.
  • If patching cannot be done immediately, follow the vendor mitigation guidance or discontinue use of the affected product per CISA BOD 22-01.
  • Restrict local interactive and non-administrative access to guest VMs that have VMware Tools managed by Aria Operations with SDMP enabled.
  • Track the CISA KEV due date of 2025-11-20 and confirm remediation across all affected VMware, Debian and cloud foundation products.
  • Audit Aria Operations SDMP configuration and disable it where it is not operationally required.

Detection

  • Monitor guest VMs for unexpected privilege escalation to root by non-administrative accounts, especially on systems with VMware Tools and Aria Operations SDMP enabled.
  • Review Aria Operations and VMware Tools logs for anomalous SDMP-related activity or unexpected process execution.
  • Hunt for new root-level processes or credential changes originating from low-privileged local users on affected guests.
  • Correlate local authentication and sudo/privilege events with known exploitation indicators from the vendor advisory and public exploit write-up.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-41244 to the Known Exploited Vulnerabilities catalog on 30 October 2025 as "Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 20 November 2025.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-41244 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed

Source: NIST National Vulnerability Database (record CVE-2025-41244), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.