CVE 7.8 HIGH

VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)_CVE-2025-41244

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Basic Information

ID CVE-2025-41244
Source vmware
Published Sep 29, 2025 at 16:09
Modified Sep 29, 2025 at 16:16

Affected Product

Vendor VMware
Product VCF operations
Version 9.0.x
Affected Versions VMware VCF operations 9.0.x
VMware VMware tools 13.x.x.x
VMware VMware tools 12.5.x
VMware VMware Aria Operations 8.18.x
VMware VMware Cloud Foundation 5.x
VMware VMware Cloud Foundation 4.x
VMware VMware Telco Cloud Platform 5.x
VMware VMware Telco Cloud Platform 4.x
VMware VMware Telco Cloud Infrastructure 3.x
VMware VMware Telco Cloud Infrastructure 2.x

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.