VMware Tools and VMware Aria Operations local privilege escalation actively exploited (CVE-2025-41244)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2025-41244 is a local privilege escalation flaw in VMware Tools and VMware Aria Operations that can let an unprivileged local user reach root on affected virtual machines. Broadcom and NVISO said the bug was exploited in the wild as a zero-day beginning in mid-October 2024, with abuse linked to UNC5174. The issue affects multiple VMware product lines, including VMware Cloud Foundation, VMware vSphere Foundation, and Telco Cloud deployments, and Broadcom said remediation requires patching with product-specific updates.
Cases
Related Happenings
Cloud Software Group NetScaler urgent remediation advisory
Advisory/Mitigation
H score44
First: 25.03.2026 17:52
Last: 25.03.2026 17:52
Sources 1
About this happening:
Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/MitigationAbout this happening: Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
CISA KEV remediation deadline for CVE-2026-22719
Public Sector Action
H score35
First: 04.03.2026 06:35
Last: 04.03.2026 06:35
Sources 1
About this happening:
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-22719 to the Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilia...
CISA KEV remediation deadline for CVE-2026-22719
Public Sector ActionAbout this happening: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-22719 to the Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilia...
VMware ESXi arbitrary-write sandbox escape (CVE-2025-22225)
Vulnerability
H score41
First: 04.02.2026 19:38
Last: 04.02.2026 19:38
Sources 1
About this happening:
CVE-2025-22225 is now confirmed in ransomware campaigns, making the VMware ESXi sandbox-escape flaw an active risk for exposed virtualization hosts. Broadcom patch...
VMware ESXi arbitrary-write sandbox escape (CVE-2025-22225)
VulnerabilityAbout this happening: CVE-2025-22225 is now confirmed in ransomware campaigns, making the VMware ESXi sandbox-escape flaw an active risk for exposed virtualization hosts. Broadcom patch...
CISA KEV remediation order for CVE-2025-22225
Public Sector Action
H score36
First: 04.02.2026 19:38
Last: 04.02.2026 19:38
Sources 1
About this happening:
CISA added CVE-2025-22225 to the Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to secure affected systems by March 25, 2025. The d...
CISA KEV remediation order for CVE-2025-22225
Public Sector ActionAbout this happening: CISA added CVE-2025-22225 to the Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to secure affected systems by March 25, 2025. The d...
Broadcom VMware vCenter Server and Cloud Foundation patch advisory (CVE-2024-37079)
Advisory/Mitigation
H score40
First: 26.01.2026 13:49
Last: 26.01.2026 13:49
Sources 1
About this happening:
Broadcom told customers to apply security patches for CVE-2024-37079 in vCenter Server and Cloud Foundation, after the flaw was tied to active exploitation and...
Broadcom VMware vCenter Server and Cloud Foundation patch advisory (CVE-2024-37079)
Advisory/MitigationAbout this happening: Broadcom told customers to apply security patches for CVE-2024-37079 in vCenter Server and Cloud Foundation, after the flaw was tied to active exploitation and...
Timeline
-
30.09.2025 13:57 5 articles · 9mo ago
Broadcom and NVISO disclose active UNC5174 exploitation of CVE-2025-41244
Initial DisclosureOn September 30, 2025, Broadcom and NVISO publicly described CVE-2025-41244 as a zero-day exploited in the wild since mid-October 2024 by UNC5174, said the flaw affects VMware Cloud Foundation, VMware vSphere Foundation, VMware Aria Operations, VMware Tools, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure, and noted that VMware Tools 12.4.9 / 12.5.4 and Linux vendor open-vm-tools updates remediate the issue.
Show sources
- Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024 — thehackernews.com — 30.09.2025 13:57
- Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024 — thehackernews.com — 30.09.2025 13:57
- China Exploited New VMware Bug for Nearly a Year — www.darkreading.com — 30.09.2025 22:41
- Broadcom Fails to Disclose Zero-Day Exploitation of VMware Vulnerability — www.securityweek.com — 01.10.2025 12:25
- CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks — thehackernews.com — 31.10.2025 09:09
-
19.05.2025 03:00 1 articles · 14mo ago
NVISO discovers CVE-2025-41244 in VMware Tools and VMware Aria Operations
Technical Analysis UpdateDuring an incident response engagement on May 19, 2025, NVISO researcher Maxime Thiebaut discovered and reported CVE-2025-41244 in VMware Tools and VMware Aria Operations, identifying a local privilege escalation path in get_version() where broad regex matching can accept non-system binaries such as /tmp/httpd and let an unprivileged local user reach root on the same VM.
Show sources
- Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024 — thehackernews.com — 30.09.2025 13:57