imPC@ndo IT

Tracker / CVE-2025-41244

CVE-2025-41244

Exploited High 7.8

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Affected products and versions

debian debian_linux
vmware aria_operations · 8.0 → 8.18.5
vmware cloud_foundation · 4.0 → 5.2.2
vmware cloud_foundation_operations
vmware open_vm_tools
vmware open_vm_tools · 11.2.0 → 12.5.4
vmware telco_cloud_infrastructure · 2.2 → 3.0
vmware telco_cloud_platform · 4.0 → 5.0.1
vmware tools · 12.5.0 → 12.5.4
vmware tools · 13.0.0.0 → 13.0.5.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References