V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2025-41244
AST
High KEVConfirmedExploit available

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative…

CVSS
7.8
High
EPSS
0.01
p67
Published
2025-01-01
Updated
2025-10-30
Description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Tags · CWE
KEV
CWE-267
CWE-284
CAPEC-19
CAPEC-58
CAPEC-441
CAPEC-478
CAPEC-479
CAPEC-502
CAPEC-503
CAPEC-536
CAPEC-546
CAPEC-550
CAPEC-551
CAPEC-552
CAPEC-556
CAPEC-558
CAPEC-562
CAPEC-563
CAPEC-564
CAPEC-578
CAPEC-634
CAPEC-637
CAPEC-643
CAPEC-648
Affected products
Aria_operations 8.0–8.18.5Cloud_foundation 4.0–5.2.2Cloud_foundation_operationsOpen_vm_tools 11.2.0–12.5.4Open_vm_toolsTelco_cloud_infrastructure 2.2–3.0Telco_cloud_platform 4.0–5.0.1
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-10-30
Added to KEV
2025-10-30
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.005 · p67
Known exploited (KEV)
Yes
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-552 · CWE-284
└ via CAPEC-19 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-562 · CWE-284
└ via CAPEC-648 · CWE-267
└ via CAPEC-637 · CWE-267
└ via CAPEC-634 · CWE-267
└ via CAPEC-634 · CWE-267
└ via CAPEC-643 · CWE-267
└ via CAPEC-558 · CWE-284
└ via CAPEC-648 · CWE-267
└ via CAPEC-552 · CWE-284
└ via CAPEC-550 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-478 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-556 · CWE-284
└ via CAPEC-558 · CWE-284
└ via CAPEC-19 · CWE-284
└ via CAPEC-564 · CWE-284
└ via CAPEC-552 · CWE-284
└ via CAPEC-479 · CWE-284
└ via CAPEC-578 · CWE-284
Known exploits — Сканер-ВС
CVE-2025-41244
github-poc · https://github.com/NULL200OK/CVE-2025-41244
Enterprise
Affected software
ProductVendorStatus
open-vm-toolsExploited
open-vm-toolsExploited
open-vm-toolsExploited
open-vm-toolsExploited
open-vm-toolsExploited
open-vm-toolsExploited
open-vm-toolsExploited
aria_operations*Exploited
cloud_foundation*Exploited
cloud_foundation_operations*Exploited
debian_linux*Exploited
open_vm_tools*Exploited
telco_cloud_infrastructure*Exploited
telco_cloud_platform*Exploited
tools*Exploited