CVE-2025-41244

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Configurations

No configuration.

History

30 Sep 2025, 13:15

Type Values Removed Values Added
References
  • () https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ -

29 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-29 17:15

Updated : 2025-09-30 13:15


NVD link : CVE-2025-41244

Mitre link : CVE-2025-41244

CVE.ORG link : CVE-2025-41244


JSON object : View

Products Affected

No product.

CWE
CWE-267

Privilege Defined With Unsafe Actions