CVE-2025-41244
29.09.2025, 17:15
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability.A malicious local actor with non-administrative privileges having access to a VM with VMware Toolsinstalled and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.Enginsight
| Vendor | Product | Version |
|---|---|---|
| vmware | aria_operations | 8.0 ≤ 𝑥 < 8.18.5 |
| vmware | cloud_foundation | 4.0 ≤ 𝑥 ≤ 5.2.2 |
| vmware | cloud_foundation_operations | 9.0 |
| vmware | open_vm_tools | 11.2.0 ≤ 𝑥 < 12.5.4 |
| vmware | open_vm_tools | 13.0.0 |
| vmware | telco_cloud_infrastructure | 2.2 ≤ 𝑥 ≤ 3.0 |
| vmware | telco_cloud_platform | 4.0 ≤ 𝑥 < 5.0.1 |
| vmware | tools | 12.5.0 ≤ 𝑥 < 12.5.4 |
| vmware | tools | 13.0.0.0 ≤ 𝑥 < 13.0.5.0 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References