VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
History

Thu, 06 Nov 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Vmware open Vm Tools
CPEs cpe:2.3:a:vmware:open_vm_tools:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:open_vm_tools:13.0.0:*:*:*:*:*:*:*
Vendors & Products Vmware open Vm Tools

Tue, 04 Nov 2025 22:30:00 +0000

Type Values Removed Values Added
References

Tue, 04 Nov 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Debian
Debian debian Linux
CPEs cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Vendors & Products Debian
Debian debian Linux

Mon, 03 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
References

Fri, 31 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
Microsoft
Microsoft windows
Vmware cloud Foundation Operations
Vmware telco Cloud Infrastructure
Vmware telco Cloud Platform
CPEs cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
Microsoft
Microsoft windows
Vmware cloud Foundation Operations
Vmware telco Cloud Infrastructure
Vmware telco Cloud Platform

Thu, 30 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Oct 2025 18:00:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2025-10-30T00:00:00+00:00', 'dueDate': '2025-11-20T00:00:00+00:00'}


Tue, 07 Oct 2025 16:15:00 +0000


Wed, 01 Oct 2025 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-280
References
Metrics threat_severity

None

threat_severity

Important


Tue, 30 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Sep 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware aria Operations
Vmware cloud Foundation
Vmware tools
Vendors & Products Vmware
Vmware aria Operations
Vmware cloud Foundation
Vmware tools

Mon, 29 Sep 2025 16:30:00 +0000

Type Values Removed Values Added
Description VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Title VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
Weaknesses CWE-267
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published: 2025-09-29T16:09:51.871Z

Updated: 2025-11-04T21:10:25.953Z

Reserved: 2025-04-16T09:30:17.799Z

Link: CVE-2025-41244

cve-icon Vulnrichment

Updated: 2025-11-04T21:10:25.953Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-29T17:15:30.843

Modified: 2025-11-06T13:58:13.620

Link: CVE-2025-41244

cve-icon Redhat

Severity : Important

Publid Date: 2025-09-29T00:00:00Z

Links: CVE-2025-41244 - Bugzilla