Junglewise Threat Intelligence

CVE-2025-41244: Broadcom VMware Aria Operations and VMware Tools privilege escalation

CVE-2025-41244 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2025-10-30

Vendors: Broadcom, VMware.

Executive brief

A security vulnerability exists in VMware Aria Operations and VMware Tools, which are used to manage and optimize virtual machine performance. A user with limited access to a virtual machine can exploit this flaw to gain full administrative (root) control over that specific system. This could allow an attacker to steal sensitive data, disrupt services, or install malicious software on the affected virtual machine.

Technical details

A local privilege escalation vulnerability (CWE-267) exists in VMware Aria Operations and VMware Tools when Service Discovery Management Pack (SDMP) is enabled. The flaw stems from a privilege defined with unsafe actions, allowing a non-administrative local actor with access to a managed virtual machine to escalate their privileges to root. The attack requires the VM to have VMware Tools installed and be managed by Aria Operations with SDMP active. This vulnerability has been observed being exploited in the wild. Patches are available in Aria Operations 8.18.5 and VMware Tools 12.5.4 / 13.0.5.

Affected products

  • Broadcom VMware Aria Operations 8.0 to 8.18.5
  • Broadcom VMware VMware Tools 12.5.0 to 12.5.4, 13.0.0.0 to 13.0.5.0
  • Broadcom VMware open-vm-tools 11.2.0 to 12.5.4, 13.0.0

Timeline

  • 2025-10-30: advisory: Initial advisory published by Broadcom/VMware
  • 2025-10-30: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-10-30: exploited: Confirmed as exploited in the wild per CISA KEV catalog

Related threats