Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign Exploitation Wave Vulnerability

UNC5174 VMware privilege-escalation activity

Updated 31.10.2025 09:09
Case score 59
Members 3 First seen 30.09.2025 13:57 Latest activity 31.10.2025 09:09

Overview

UNC5174 is exploiting **CVE-2025-41244** against **VMware Aria Operations** and **VMware Tools** to move from local access to **root** on affected virtual machines. The activity has been active since October 2024 and uses malicious binaries staged in **/tmp/httpd** plus VMware service-discovery behavior to trigger privilege escalation. Broadcom and Linux vendors have released fixes, including updates for VMware environments and **open-vm-tools**. CISA added the flaw to the **Known Exploited Vulnerabilities** catalog and set **November 20, 2025** as the federal remediation deadline, while available evidence does not quantify how many organizations were affected.
Latest development Open development history 4 earlier developments CISA adds CVE-2025-41244 to KEV catalog after VMware exploitation CISA added CVE-2025-41244 affecting Broadcom VMware Tools and VMware Aria Operations to the KEV catalog after reports of active exploitation in the wild. Broadcom had already addressed the flaw, which NVISO Labs says was abused as a zero-day since mid-October 2024 to escalate a local actor to root on vulnerable VMs. Federal Civilian Executive Branch agencies must apply mitigations by November 20, 2025.
  1. Earlier development

    Broadcom and NVISO disclose active UNC5174 exploitation of CVE-2025-41244

    On September 30, 2025, Broadcom and NVISO publicly described CVE-2025-41244 as a zero-day exploited in the wild since mid-October 2024 by UNC5174, said the flaw affects VMware Cloud Foundation, VMware vSphere Foundation, VMware Aria Operations, VMware Tools, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure, and noted that VMware Tools 12.4.9 / 12.5.4 and Linux vendor open-vm-tools updates remediate the issue.

  2. Earlier development

    NVISO Labs discloses UNC5174's CVE-2025-41244 VMware exploitation

    NVISO Labs disclosed that UNC5174, a Chinese state-sponsored threat actor, has been exploiting CVE-2025-41244 against VMware-managed virtual machines since October 2024, using malicious binaries staged in /tmp/httpd and discovery-logic abuse to trigger root code execution on systems with VMware Tools or open-vm-tools and Aria Operations discovery enabled; Broadcom said fixes were available for VMware Cloud Foundation, vSphere Foundation, Aria Operations, Telco Cloud Platform, and VMware Tools, and Linux vendors would distribute open-vm-tools updates, while organizations were advised to hunt for uncommon child processes and lingering metrics collector scripts or outputs in legacy credential-based mode.

  3. Earlier development

    VMware Aria Operations and VMware Tools CVE-2025-41244 exploitation wave

    In **mid-October 2024**, attackers began abusing **CVE-2025-41244** on **VMware Aria Operations** and **VMware Tools** to move from local access toward **privilege escalation**. The first phase centered on staging a malicious binary that VMware service discovery could pick up.

  4. Earlier development

    NVISO discovers CVE-2025-41244 in VMware Tools and VMware Aria Operations

    During an incident response engagement on May 19, 2025, NVISO researcher Maxime Thiebaut discovered and reported CVE-2025-41244 in VMware Tools and VMware Aria Operations, identifying a local privilege escalation path in get_version() where broad regex matching can accept non-system binaries such as /tmp/httpd and let an unprivileged local user reach root on the same VM.

Signals

Exploitation
CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

4 listed

Technical intelligence

Existing Case data

Member happenings

Campaign UNC5174 VMware CVE-2025-41244 exploitation campaign
Updated 01.10.2025 12:25 Lead Contribution 56
Campaign Active Patch Patch Available

The **UNC5174** operation is actively exploiting **CVE-2025-41244** to gain **root** code execution on VMware-managed virtual machines, increasing risk for organizations using **VMware Aria Operations**, **VMware Tools**, and **open-vm-tools**. The activity has persisted **since October 2024** and uses **malicious binaries in /tmp/httpd** plus discovery-logic abuse to trigger privilege escalation.

Exploitation Wave VMware Aria Operations and VMware Tools CVE-2025-41244 exploitation wave
Updated 30.09.2025 17:54 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 7.8 High Patch Patch Available

A **CVE-2025-41244** exploitation wave has affected **VMware Aria Operations** and **VMware Tools** since **mid-October 2024**, creating **privilege-escalation** risk on vulnerable VMs. Attackers can stage a malicious binary in broadly matched paths and push it into VMware service discovery, which can end in **root-level code execution**. A **proof-of-concept exploit** now shows how the flaw can be abused in both **credential-based** and **credential-less** configurations. The activity matters because it turns a local foothold into full administrative control on exposed systems.

Vulnerability VMware Tools and VMware Aria Operations local privilege escalation actively exploited (CVE-2025-41244)
Updated 30.09.2025 13:57 Context
Exploitation Active Exploitation Exploit Public Exploit Data Type Physical Addresses CVSS 7.8 High 1 more in details
All signals
Exploitation Active Exploitation Exploit Public Exploit Data Type Physical Addresses CVSS 7.8 High Patch Patch Available

**CVE-2025-41244** is a **local privilege escalation** flaw in **VMware Tools** and **VMware Aria Operations** that can let an unprivileged local user reach **root** on affected virtual machines. **Broadcom** and **NVISO** said the bug was exploited in the wild as a **zero-day** beginning in **mid-October 2024**, with abuse linked to **UNC5174**. The issue affects multiple **VMware** product lines, including **VMware Cloud Foundation**, **VMware vSphere Foundation**, and **Telco Cloud** deployments, and Broadcom said remediation requires **patching** with product-specific updates.