CVE-2025-41244: Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2025-10-30. EPSS: 8.4% chance of exploitation in the next 30 days.
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Affected products
- Debian Debian Linux: version 11.0 only
- VMware Aria Operations: from 8.0, before 8.18.5 (fixed in 8.18.5)
- VMware Cloud Foundation: from 4.0, up to and including 5.2.2
- VMware Cloud Foundation Operations: version 9.0 only
- VMware Open Vm Tools: from 11.2.0, before 12.5.4 (fixed in 12.5.4); version 13.0.0 only
- VMware Telco Cloud Infrastructure: from 2.2, up to and including 3.0
- VMware Telco Cloud Platform: from 4.0, before 5.0.1 (fixed in 5.0.1)
- VMware Tools: from 12.5.0, before 12.5.4 (fixed in 12.5.4); from 13.0.0.0, before 13.0.5.0 (fixed in 13.0.5.0)
Published 2025-09-29. Last modified 2026-06-17.