CVE-2025-41244 is a local privilege escalation vulnerability affecting VMware Aria Operations and VMware Tools on Linux, Debian, and Microsoft systems. A non-administrative local actor can exploit this flaw to gain root privileges on a VM where VMware Tools is installed and managed by Aria Operations with SDMP enabled. This vulnerability has a CVSS score of 7.8 (High) due to its low attack complexity and high impact on confidentiality, integrity, and availability. It is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite no public exploit code being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0, < 8.18.5CPE matchmatch criteria | cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* | ||
>= 4.0, <= 5.2.2CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:* | ||
>= 11.2.0, < 12.5.4CPE matchmatch criteria | cpe:2.3:a:vmware:open_vm_tools:*:*:*:*:*:*:*:* | ||
13.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:open_vm_tools:13.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple vulnerabilities in VMware Aria Operations and VMware Tools
Oct 14, 2025open-vm-tools: Local privilege escalation in open-vm-tools
Sep 29, 2025Multiple vulnerabilities in VMware Aria Operations and VMware Tools