← Back

CVE-2025-41244

nvd nist
Published: Sep 29, 2025Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: security@vmware.com (Secondary)

Description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Affected (10)

7 products
Aria Operations
Cloud Foundation
Cloud Foundation Operations
Open Vm Tools
Telco Cloud Infrastructure
Telco Cloud Platform
Tools
1 product
Debian Linux
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
From 8.0 to 8.18.5
From 4.0 to 5.2.2
Version 9.0
Vmware
From 11.2.0 to 12.5.4
Version 13.0.0
From 2.2 to 3.0
From 4.0 to 5.0.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0
Configuration C
2 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Vmware
From 12.5.0 to 12.5.4
From 13.0.0.0 to 13.0.5.0
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions

Timeline

No history available yet.