7.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Basic Information
ID
CVE-2025-41244
Source
vmware
Published
Sep 29, 2025 at 16:09
Modified
Sep 29, 2025 at 16:16
Affected Product
Vendor
VMware
Product
VCF operations
Version
9.0.x
Affected Versions
VMware VCF operations 9.0.x
VMware VMware tools 13.x.x.x
VMware VMware tools 12.5.x
VMware VMware Aria Operations 8.18.x
VMware VMware Cloud Foundation 5.x
VMware VMware Cloud Foundation 4.x
VMware VMware Telco Cloud Platform 5.x
VMware VMware Telco Cloud Platform 4.x
VMware VMware Telco Cloud Infrastructure 3.x
VMware VMware Telco Cloud Infrastructure 2.x
VMware VMware tools 13.x.x.x
VMware VMware tools 12.5.x
VMware VMware Aria Operations 8.18.x
VMware VMware Cloud Foundation 5.x
VMware VMware Cloud Foundation 4.x
VMware VMware Telco Cloud Platform 5.x
VMware VMware Telco Cloud Platform 4.x
VMware VMware Telco Cloud Infrastructure 3.x
VMware VMware Telco Cloud Infrastructure 2.x