Vulnerability record · CVE-2025-41244 · published 29 September 2025
CVE-2025-41244: VMware Aria Operations and Tools local privilege escalation to root
Vmware · Aria Operations
VMware Aria Operations and VMware Tools contain a local privilege escalation flaw where a non-administrative local actor on a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled can escalate to root on that same VM. It matters because the affected components are widely deployed in virtualized and cloud environments, and the flaw is listed in CISA KEV with a federal remediation deadline.
Description
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a local privilege escalation to root with a CVSS of 7.8, listed in CISA KEV with a near-term federal due date and public exploit reference, though it requires an existing local foothold and specific SDMP configuration.
What it is
VMware Aria Operations and VMware Tools contain a local privilege escalation flaw where a non-administrative local actor on a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled can escalate to root on that same VM. It matters because the affected components are widely deployed in virtualized and cloud environments, and the flaw is listed in CISA KEV with a federal remediation deadline.
Impact
An attacker with only non-administrative local access gains full root privileges on the affected VM, enabling complete control of that guest, including data access, persistence and further lateral movement.
Attack surface
The vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the attacker must already have a foothold on the guest VM and the environment must have VMware Tools managed by Aria Operations with SDMP enabled.
Exploitation
CVE-2025-41244 is in CISA KEV (added 2025-10-30, due 2025-11-20) and a third-party reference is tagged Exploit, indicating public exploitation knowledge; EPSS 30-day probability is about 8.4 percent (94.7th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor updates from Broadcom VMSA-2025-0015 for VMware Aria Operations and VMware Tools as the first action.
- If patching cannot be done immediately, follow the vendor mitigation guidance or discontinue use of the affected product per CISA BOD 22-01.
- Restrict local interactive and non-administrative access to guest VMs that have VMware Tools managed by Aria Operations with SDMP enabled.
- Track the CISA KEV due date of 2025-11-20 and confirm remediation across all affected VMware, Debian and cloud foundation products.
- Audit Aria Operations SDMP configuration and disable it where it is not operationally required.
Detection
- Monitor guest VMs for unexpected privilege escalation to root by non-administrative accounts, especially on systems with VMware Tools and Aria Operations SDMP enabled.
- Review Aria Operations and VMware Tools logs for anomalous SDMP-related activity or unexpected process execution.
- Hunt for new root-level processes or credential changes originating from low-privileged local users on affected guests.
- Correlate local authentication and sudo/privilege events with known exploitation indicators from the vendor advisory and public exploit write-up.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-41244 to the Known Exploited Vulnerabilities catalog on 30 October 2025 as "Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 20 November 2025.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMwar | Permissions Required |
| http://www.openwall.com/lists/oss-security/2025/09/29/10 | Mailing ListThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html | Mailing ListThird Party Advisory |
| https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ | ExploitThird Party Advisory |
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 | US Government Resource |
Track CVE-2025-41244 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-41244), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.