CVE-2025-41244

9.5 CISA KEV

Broadcom · VMware Aria Operations and VMware Tools

A local privilege escalation vulnerability in VMware Aria Operations and VMware Tools allows a malicious local user to elevate privileges to root on the affected virtual machine.

Executive summary

Broadcom VMware Aria Operations and VMware Tools are affected by a critical local privilege escalation vulnerability that is currently being exploited in the wild.

Vulnerability

This is a privilege defined with unsafe actions flaw (CWE-267) where a local user with non-administrative access can leverage the SDMP functionality in Aria Operations to escalate privileges to root level on a guest virtual machine.

Business impact

Successful exploitation permits a low-privileged local attacker to gain full administrative control over the guest virtual machine. Given the CVSS score of 9.5, this vulnerability represents a severe risk to confidentiality, integrity, and availability, potentially leading to unauthorized data access, system modification, or total compromise of the affected infrastructure.

Remediation

Immediate Action: Update VMware Aria Operations and VMware Tools to the patched versions specified in the vendor advisory immediately.

Proactive Monitoring: Monitor system logs for unauthorized privilege escalation attempts or unusual processes spawned by the VMware Tools service.

Compensating Controls: Restrict local access to virtual machines to trusted users only and implement strict principle of least privilege policies for all accounts on guest operating systems.

Exploitation status

Public Exploit Available: Yes, multiple public proof-of-concept repositories are available on GitHub.

Analyst recommendation

The severity of this vulnerability, combined with confirmed active exploitation, necessitates immediate patching. Organizations should prioritize updating all instances of VMware Aria Operations and VMware Tools within their environment to the secure versions provided by Broadcom to prevent unauthorized root-level access.

More Broadcom CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section, carried in 2 daily briefs, Sep 29 to Sep 30
  3. Published in the daily brief kev section, carried in 21 daily briefs, Oct 30 to Nov 19
  4. Look Back published
  5. Analyst report written
  6. Fix documented version 9.0.1.0 per CVE record